Executive Summary
SourTrade is a sophisticated malvertising operation active since late 2024, impersonating major cryptocurrency and trading platforms such as TradingView, Solana, and Luno. The campaign uses advanced cloaking techniques to separate legitimate targets from security researchers and bots, serving convincing replica pages only to high-value retail traders and crypto investors across 12 countries.
Technically, SourTrade distinguishes itself by shifting the malware delivery process from the server to the victim's browser. Instead of downloading a completed malicious file, the browser follows a 'byte-copy recipe' delivered via a /config endpoint. It fetches a clean Bun runtime, generates a unique AES-CTR stream, and combines them with malicious JavaScriptCore bytecode in memory. This process ensures that no finished malware binary ever exists on the network, effectively bypassing traditional file-hash and network-level signatures.
This activity poses a significant risk to the financial and cryptocurrency sectors, as it allows attackers to distribute stealers like JSCEAL (also known as WeevilProxy) while remaining invisible to standard perimeter defenses. The use of ServiceWorkers and same-origin download paths further obscures the origin of the malicious payloads, complicating incident response and forensic analysis.
