Home/News/Malvertising Operation Uses Browser to Assemble Executables
The Hacker News2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Malvertising Operation Uses Browser to Assemble Executables

Malvertising Operation Uses Browser to Assemble Executables

A malvertising operation identified as SourTrade has been active since late 2024, employing a novel technique that leverages victims' web browsers to construct the final Windows executable. This campaign, detailed by Confiant on July 23, 2026, avoids serving a complete malicious file from a single URL. Instead, it delivers the executable in fragmented pieces, instructing the legitimate Bun runtime within the browser to reassemble them into the final malicious program.

This method of delivery and execution significantly complicates detection by traditional security measures, which often rely on identifying complete malicious files or known malicious URLs. By using the Bun runtime, a JavaScript runtime environment, SourTrade masks its malicious activity within legitimate processes. The campaign has primarily targeted retail traders, impersonating well-known platforms such as TradingView, Solana, and Luno to gain the trust of its intended victims.

Confiant's analysis indicates that SourTrade's sophisticated approach involves a multi-stage process. Initial infection vectors likely involve malicious advertisements that, when clicked, initiate the download of these fragmented components. The browser then acts as the assembly line, piecing together the code before it can be fully executed on the user's system. This technique represents an evolving threat landscape where attackers are increasingly innovating to bypass security protocols and reach their targets.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next