SourTrade Malvertising Campaign Evades Detection by Building Malware in Browsers
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
SourTrade is a malvertising operation that has been active since late 2024, targeting cryptocurrency users through fake ads that lead to counterfeit trading platforms. The campaign affects users across Asia-Pacific, Latin America, Africa, Australia, and Great Britain. By leveraging browser-based malware assembly, SourTrade circumvents traditional hash-based detection methods. The attackers impersonate well-known brands like TradingView and Solana to lure victims. This operation has reached retail traders and crypto investors in 12 different geographies. Current reports indicate ongoing activity, with no immediate resolution in sight.
Key Points: • SourTrade uses browser-assembled malware to evade traditional detection methods. • The campaign has targeted users in multiple regions, including APAC and LATAM. • Attackers impersonate familiar brands to lure cryptocurrency users into traps.