THE SourTrade malvertising campaign uses innovative techniques to build malware within victims' browsers without exposing the complete malware payload on the network. Active since 2024, SourTrade mimics well-known trading platforms to lure users into installing an infostealer. Upon visiting a malicious site, the browser receives assembly instructions for the malware, which is constructed and executed directly in memory, appearing safe while compromising users' systems. This approach helps evade detection by security tools. Researchers have noted that SourTrade represents a persistent threat due to its evolving tactics.
SourTrade malvertising hides malware in browsers to steal data
CyberSIXT Evidence Panel
Primary Source
blog.confiant.com
Article by CyberSIXT