ThreatCluster

SourTrade Malvertising Campaign Evades Detection by Building Malware in Browsers

First seen 24 Jul 2026, 15:52 UTC GbhackersCybersecuritynews 82% similarity 67

Article Content

Browse articles
ThreatCluster

SourTrade is a malvertising operation that has been active since late 2024, targeting cryptocurrency users through fake ads that lead to counterfeit trading platforms. The campaign affects users across Asia-Pacific, Latin America, Africa, Australia, and Great Britain. By leveraging browser-based malware assembly, SourTrade circumvents traditional hash-based detection methods. The attackers impersonate well-known brands like TradingView and Solana to lure victims. This operation has reached retail traders and crypto investors in 12 different geographies. Current reports indicate ongoing activity, with no immediate resolution in sight.

Key Points: • SourTrade uses browser-assembled malware to evade traditional detection methods. • The campaign has targeted users in multiple regions, including APAC and LATAM. • Attackers impersonate familiar brands to lure cryptocurrency users into traps.

ThreatCluster AI

Timeline

2024-12-01
SourTrade campaign begins
SourTrade starts targeting cryptocurrency users through malvertising techniques.
Gbhackers
2026-07-24
SourTrade campaign reported
Recent articles highlight the ongoing malvertising operation targeting crypto users globally.
Cybersecuritynews

Community

Browse all →