The New Face of Malvertising: SourTrade’s Assembly-Line Attack
According to a recent report by The Hacker News, a malvertising campaign called SourTrade has been tricking victims’ browsers into building the final malware file on the spot. Instead of sending a complete malicious executable over the internet, the attack breaks the malware into pieces and uses the browser itself to put it all together. This makes it much harder for traditional security tools to catch the threat before it reaches a computer.
What makes this campaign stand out is how it exploits a legitimate programming tool called Bun. The browser downloads a clean, harmless version of Bun from a separate website, then combines it with hidden code delivered through the landing page. The result is a unique malware file that looks different every time it is built. Criminals are impersonating well-known trading platforms like TradingView, Solana, and Luno, targeting people who invest in stocks or cryptocurrencies.
Why This Attack Is Harder to Spot
This technique shows that attackers are moving beyond simple email attachments or one-click downloads. They are now using the browser as a factory floor, assembling dangerous software right inside the user’s machine. Because every assembled file has a different digital fingerprint, antivirus software that relies on matching known virus signatures will likely miss it.
The attack also uses background scripts called Service Workers and Shared Workers to manage the assembly process without obvious network traffic. Victims who are shown a fake but convincing copy of a trading site may never notice anything unusual until it is too late. The real danger is that these methods can be adapted to target any kind of business software, not just trading apps.
What This Means for Australian SMBs
Australian small and mid-sized businesses often depend on standard antivirus and web filters to stay safe. This SourTrade campaign exposes a gap in that approach. Employees who browse financial news or use cryptocurrency wallets at work could accidentally trigger a download that no signature-based tool can block.
Many SMBs also lack the ability to monitor advanced browser behavior like Service Worker registrations or outbound requests to unknown domains. Without that visibility, an attack like this can slip through unnoticed until sensitive data is stolen. For Australian businesses already juggling limited IT budgets, this new method demands a fresh look at how they defend against online threats.
What You Can Do Now
- Install a reputable ad blocker on all company browsers to reduce the risk of malvertising landing pages.
- Train employees to download trading, wallet, or financial software only from the official vendor website, never from an online advertisement.
- Configure your network firewall to flag or block unusual browser activities, such as registering unknown Service Workers or fetching scripts from unfamiliar domains.
- Consider endpoint security tools that analyze behavior (like unexpected file assembly or process creation) rather than relying solely on file signatures.
- Keep browsers and all plugins updated to the latest versions, as older browsers may offer more attack surface for these assembly techniques.
Stopping threats like SourTrade requires a proactive security stance. MS&VG helps Australian SMBs build layered defenses that adapt to evolving cyber threats, so your business stays protected even when attackers change their playbook.