SourTrade Malvertising Assembles Malware Locally via Browser
Score: 8/10

SourTrade Malvertising Assembles Malware Locally via Browser

The SourTrade malvertising campaign uses victim browsers to locally assemble unique Windows executables from legitimate components and malicious bytecode to evade hash-based detection.

Executive Summary

SourTrade is a sophisticated malvertising operation active since late 2024, impersonating major cryptocurrency and trading platforms such as TradingView, Solana, and Luno. The campaign uses advanced cloaking techniques to separate legitimate targets from security researchers and bots, serving convincing replica pages only to high-value retail traders and crypto investors across 12 countries.

Technically, SourTrade distinguishes itself by shifting the malware delivery process from the server to the victim's browser. Instead of downloading a completed malicious file, the browser follows a 'byte-copy recipe' delivered via a /config endpoint. It fetches a clean Bun runtime, generates a unique AES-CTR stream, and combines them with malicious JavaScriptCore bytecode in memory. This process ensures that no finished malware binary ever exists on the network, effectively bypassing traditional file-hash and network-level signatures.

This activity poses a significant risk to the financial and cryptocurrency sectors, as it allows attackers to distribute stealers like JSCEAL (also known as WeevilProxy) while remaining invisible to standard perimeter defenses. The use of ServiceWorkers and same-origin download paths further obscures the origin of the malicious payloads, complicating incident response and forensic analysis.

Key Details

Threat Name

SourTrade Malvertising Campaign

Affects

—

Adversary

SourTrade Other Adversaries and Aliases: Cl0p

Malware/Tools

JSCEAL, Variant.DenoSnoop.Marte.1, SourTrade, SeaFlower

Report Score

8out of 10
Quality Score
Good
IOC Quality9
TTP Details9
Detection Guidance6
Enterprise Relevance7
Clarity & Structure8
Technical Depth9

Sources