Find notable cyber news and cases, enriched with sources, timelines, and signals.

SourTrade malvertising campaign impersonating trading and cryptocurrency brands

Campaign
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

The SourTrade malvertising campaign remains active, using lookalike portals and malicious JavaScript to target retail traders and cryptocurrency investors across 12 countries and 25 languages. It impersonates brands such as Solana, Luno, and TradingView to lure victims from ads on Facebook and Google. The delivery chain shifts malware assembly into the browser, increasing stealth and complicating detection. The activity has continued since late 2024 and overlaps with related JSCeal distribution.

Related Happenings

JSCeal malware activity

Malware Activity
H score29 First: 07.09.2026 10:53 Last: 07.09.2026 10:53 Sources 1

How related: Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities.

About this happening: JSCeal is a compiled V8 JavaScript malware that now stands out for credential harvesting, session replay, and traffic interception against browser data. The ma...

SourTrade malvertising campaign targeting retail traders and crypto investors

Campaign
H score30 First: 25.07.2026 18:21 Last: 25.07.2026 18:21 Sources 1

About this happening: The SourTrade malvertising campaign targets retail traders and cryptocurrency investors by impersonating TradingView, Solana, and Luno. It operates across 12 countries and 25 lang...

Latest development: 25.07.2026 21:48

On April 30, 2026, the pages in the SourTrade delivery chain loaded StreamSaver.js from the author's GitHub Pages address, showing an earlier streamed-download path that pointed the recorded download source at the library URL.

BlueNoroff ClickFix-style Zoom and Microsoft Teams phishing campaign

Campaign
H score38 First: 24.07.2026 18:12 Last: 24.07.2026 18:12 Sources 1

About this happening: BlueNoroff's ClickFix-style phishing campaign is using typosquatted Zoom and Microsoft Teams domains to deliver malware and steal Telegram sessions from high-value cry...

Lurking Lizard trojanized 7-Zip installer campaign

Campaign
H score84 First: 09.07.2026 07:01 Last: 09.07.2026 07:01 Sources 1

About this happening: A Lurking Lizard campaign used a trojanized 7-Zip installer to recruit devices as proxy nodes, expanding a residential-proxy operation that has run since at least Au...

REF8372 malicious Google Ads CastleStealer delivery campaign

Campaign
H score27 First: 22.06.2026 16:20 Last: 22.06.2026 16:20 Sources 1

About this happening: The REF8372 campaign now uses malicious Google Ads and a fake Node.js download site to deliver OXLOADER and CastleStealer, putting search users at risk of malw...

Timeline

  1. 07.09.2026 10:53 2 articles · 3h ago

    SourTrade uses lookalike trading portals to assemble malware in victims’ browsers

    Campaign Scope Update

    SourTrade malvertising redirects retail traders and cryptocurrency investors from ads on Facebook and Google to lookalike portals impersonating Solana, Luno, and TradingView, where malicious JavaScript directs the browser to build malware in memory instead of downloading a finished payload. The campaign is assessed to have been active since late 2024 across 12 countries and 25 languages, and the activity overlaps with a JSCeal distribution cluster.

    Show sources