Skip to content
SourTrade Malvertising Campaign Evades Detection by Building Malware in Browsers

SourTrade Malvertising Campaign Evades Detection by Building Malware in Browsers

First seen 24 Jul 2026, 15:52 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 25, 2026 at 13:50 UTC
  • SourTrade uses browser-assembled malware to evade traditional detection methods.
  • The campaign has targeted users in multiple regions, including APAC and LATAM.
  • Attackers impersonate familiar brands to lure cryptocurrency users into traps.

SourTrade is a malvertising operation that has been active since late 2024, targeting cryptocurrency users through fake ads that lead to counterfeit trading platforms. The campaign affects users across Asia-Pacific, Latin America, Africa, Australia, and Great Britain. By leveraging browser-based malware assembly, SourTrade circumvents traditional hash-based detection methods. The attackers impersonate well-known brands like TradingView and Solana to lure victims. This operation has reached retail traders and crypto investors in 12 different geographies. Current reports indicate ongoing activity, with no immediate resolution in sight.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 57d ago How this analysis works

Timeline

2024-12-01
SourTrade campaign begins
SourTrade starts targeting cryptocurrency users through malvertising techniques.
Gbhackers
2026-07-24
SourTrade campaign reported
Recent articles highlight the ongoing malvertising operation targeting crypto users globally.
Cybersecuritynews

More articles in this cluster (11)

Following this threat?

Track Raccoon Stealer in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed