Malvertising campaigns use browsers to install persistent adware and custom malware
Heimdal’s telemetry shows the MediaArena browser‑modifier adware can write its persistence mechanism to disk eight seconds before Microsoft Defender’s quarantine completes, giving the threat a foothold even when detection fires. The timing was consistent across more than 40 client machines, with the adware remaining active for around eleven weeks before signature‑based detection finally caught it.
Research by Confiant reveals a separate malvertising operation, dubbed SourTrade, that assembles Windows executables inside victims’ browsers. By delivering assembly instructions and components that are stitched together in memory, each generated file has a unique hash, defeating traditional file‑fingerprinting defenses. The campaign impersonates services such as TradingView, Solana and Luno, operates in 12 countries and uses browser features like ServiceWorkers and in‑memory SharedWorkers to avoid detection.
Entities: Confiant · Heimdal · MediaArena · Microsoft Defender · SourTrade