By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Malicious Sites Build Malware in Browser Memory
A widespread malvertising campaign is leveraging fake webpages designed to mimic legitimate cryptocurrency and financial platforms like Solana, Luno, and TradingView. These deceptive sites employ sophisticated malicious JavaScript code that instructs the user's web browser to construct and assemble malware directly within its memory. This technique bypasses traditional security measures that often monitor for file downloads, making detection significantly more challenging.
The campaign's primary objective is to exploit vulnerabilities in how browsers handle and execute JavaScript, a common scripting language used for interactive web content. By embedding the malware assembly process within the browser's memory, attackers can avoid writing malicious files to the user's hard drive, a common trigger for antivirus software. This in-memory execution makes the malware transient and harder to trace once the browser session is closed or the malicious script is terminated.
Security researchers have identified that the malicious JavaScript code dynamically generates and executes components of the malware within the browser's RAM. This approach allows for a more stealthy deployment, as the malware never exists as a discrete file on the victim's system. The campaign specifically targets users who might visit these fake financial sites, likely in an attempt to steal credentials or deploy further malicious payloads. The use of well-known platform names like Solana, Luno, and TradingView aims to lure unsuspecting users into interacting with the compromised webpages.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.