Get alerts on this situation
We’ll email you as it develops, and you can follow the whole thread from day one.
Unsubscribe anytime.
[SITUATION] · [ACTIVE]
2 clusters · 6 sources · 6 days · First seen · Last updated
Categories: TECHNOLOGY
Browser-based malvertising targeting crypto wallets
Entities: MediaArena · Heimdal · Confiant · Microsoft Defender · SourTrade
Overview
The first report (24 July 2026) described the SourTrade operation, active since late 2024, which lures cryptocurrency investors with fake ads for platforms such as Solana, Luno and TradingView. Attackers use a file‑less approach: JavaScript registers ServiceWorker and SharedWorker, then employs the Bun runtime to assemble a malicious Windows executable entirely in the browser’s memory, evading signature‑based detection. The payload functions as a proxy, logs keystrokes and harvests private‑key credentials.
A week later (30 July 2026), telemetry from Heimdal highlighted the MediaArena browser‑modifier adware, which writes its persistence mechanism to disk within seconds of Microsoft Defender’s quarantine and remains active for roughly eleven weeks before signature detection catches it. The same analysis reiterated the SourTrade campaign, noting its in‑browser assembly of unique‑hash executables, impersonation of the same services, operation in 12 countries and reliance on ServiceWorkers and SharedWorkers to avoid detection.
Together the snapshots show an ongoing evolution of browser‑based malvertising, with multiple actors employing rapid in‑memory techniques to achieve persistence and evade traditional defenses while spreading across diverse regions.
Timeline
-
3 days ago
[TECHNOLOGY] 3 sourcesMalvertising campaigns use browsers to install persistent adware and custom malwareHeimdal found MediaArena adware persists before quarantine, while Confiant’s SourTrade builds unique malware in browsers, evading hash‑based detection across 12 countries.
-
9 days ago
[TECHNOLOGY] 4 sourcesSourTrade Malvertising Campaign Steals Crypto Wallets via Browser AttackThe SourTrade malvertising operation, active since late 2024, tricks crypto investors with fake ads for platforms like Solana and TradingView, using ServiceWorker‑based file‑less attacks that assemble malware –
Sources
borncity.com · comparethecloud.net · floranews.nl · ppc.land · sf-encyclopedia.com · thehackernews.com