< Back to situations

We’ll email you as it develops, and you can follow the whole thread from day one.

[SITUATION] · [ACTIVE]

2 clusters · 6 sources · 6 days · First seen · Last updated

Categories: TECHNOLOGY

Browser-based malvertising targeting crypto wallets

Entities: MediaArena · Heimdal · Confiant · Microsoft Defender · SourTrade

Overview

The first report (24 July 2026) described the SourTrade operation, active since late 2024, which lures cryptocurrency investors with fake ads for platforms such as Solana, Luno and TradingView. Attackers use a file‑less approach: JavaScript registers ServiceWorker and SharedWorker, then employs the Bun runtime to assemble a malicious Windows executable entirely in the browser’s memory, evading signature‑based detection. The payload functions as a proxy, logs keystrokes and harvests private‑key credentials.

A week later (30 July 2026), telemetry from Heimdal highlighted the MediaArena browser‑modifier adware, which writes its persistence mechanism to disk within seconds of Microsoft Defender’s quarantine and remains active for roughly eleven weeks before signature detection catches it. The same analysis reiterated the SourTrade campaign, noting its in‑browser assembly of unique‑hash executables, impersonation of the same services, operation in 12 countries and reliance on ServiceWorkers and SharedWorkers to avoid detection.

Together the snapshots show an ongoing evolution of browser‑based malvertising, with multiple actors employing rapid in‑memory techniques to achieve persistence and evade traditional defenses while spreading across diverse regions.

Timeline

  1. 3 days ago

    [TECHNOLOGY] 3 sources
    Malvertising campaigns use browsers to install persistent adware and custom malware

    Heimdal found MediaArena adware persists before quarantine, while Confiant’s SourTrade builds unique malware in browsers, evading hash‑based detection across 12 countries.

  2. 9 days ago

    [TECHNOLOGY] 4 sources
    SourTrade Malvertising Campaign Steals Crypto Wallets via Browser Attack

    The SourTrade malvertising operation, active since late 2024, tricks crypto investors with fake ads for platforms like Solana and TradingView, using ServiceWorker‑based file‑less attacks that assemble malware –

Sources

borncity.com · comparethecloud.net · floranews.nl · ppc.land · sf-encyclopedia.com · thehackernews.com