Confiant • 1 minute read
Understanding SourTrade: Why the Browser-Assembled Malware Campaign Is Drawing Attention
When Confiant published its technical analysis of SourTrade, the research was quickly covered by BleepingComputer, The Hacker News, and Infosecurity Magazine, prompting broader discussion among security researchers and practitioners.
At the center of the discussion is a finding that extends beyond a single campaign: SourTrade appears to be one of the first documented examples of a large-scale malvertising campaign operationalizing browser-side malware assembly.
What Is SourTrade?
SourTrade is a persistent malvertising operation that impersonates trusted cryptocurrency and trading platforms, including TradingView, Solana, and Luno, to deliver malware. Related activity associated with the broader operation has also been documented by Bitdefender.
SourTrade uses cloaking and brand impersonation to separate real victims from analysts. But instead of delivering a finished malicious executable, SourTrade delivers the individual components and instructions needed to assemble one locally. Because the final executable is built on the victim's device, each copy is unique, making traditional file- and hash-based detection far less effective.
Why Is It Different?
Most malware campaigns deliver a completed malicious file. SourTrade delivers the instructions to build one.
Using legitimate browser capabilities and software components, the campaign assembles a unique executable directly on the victim's device instead of delivering a prebuilt malicious file. While browser-side malware assembly has been observed in other attack types, SourTrade demonstrates how the technique can be operationalized at scale within a malvertising campaign.
Why It Matters
SourTrade shifts attention from the malware itself to the delivery process. Rather than focusing solely on disguising malware, the campaign changes how malware reaches the victim. That shift makes the delivery process itself part of the attack surface and reinforces why defenders increasingly need visibility into the full execution chain, not just the final payload.
Read the Full Technical Research
Read the complete technical analysis to explore the browser assembly process, execution chain, infrastructure analysis, indicators of compromise, and defensive recommendations uncovered by Confiant's Security Research team.
Additional Coverage
SourTrade has also been covered by:
Continue Exploring
→ Download the MAQ Index to understand risk across the broader threat landscape.→ Explore more threat research from Confiant's Security team



