discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base. The campaign has operated since late 2024 and impersonated TradingView, Solana, and Luno to target retail trade…

By Swati Khandelwal·Jul 25·thehackernews.com·2 min read

Intelligence analysis by Llama

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
Image: thehackernews.com

The malvertising operation, dubbed SourTrade, uses a legitimate Bun runtime to make victims' browsers build the final Windows executable. The campaign has been operating since late 2024 and has targeted retail traders and cryptocurrency investors across 12 countries in 25 languages.

Why it matters

This story matters because it highlights a sophisticated malvertising operation that can evade detection by traditional security measures. The use of a legitimate Bun runtime to build the final executable makes it difficult for defenders to identify the malicious activity.

Imagine you're browsing the internet and you see an ad that looks like it's from a real company. But instead of just showing you the ad, the ad is actually making your computer build a special kind of software that can do bad things. This is what's happening in the SourTrade campaign, where the attackers are using a legitimate software called Bun to make your computer build the final executable. It's like a puzzle, and the attackers are using different pieces to make it hard for defenders to solve.

Analysis

A Malvertising Operation Like No Other

The SourTrade campaign is a unique example of a malvertising operation that uses a legitimate Bun runtime to make victims' browsers build the final Windows executable. This approach allows the attackers to evade detection by traditional security measures, making it a challenging threat for defenders to identify.

How It Works

The campaign begins with a landing page that fingerprint visitors, showing suspected researchers and bots an empty page while selected targets receive a convincing copy of the impersonated service. The defense against this is the ordinary one: install trading and wallet software from the vendor's own site, not from an ad.

The Role of Bun

Bun is a legitimate runtime that supports compiling applications and bytecode into standalone Windows executables. The attackers use Bun to build the final executable, making it difficult for defenders to identify the malicious activity. The use of Bun also allows the attackers to rotate the seed and size in each /config response, changing the hash while retaining the executable payload code.

The Importance of Examining the Whole Chain

Defenders should examine the whole chain, from the ad referral and cloaked landing page through the /config request, the secondary-domain runtime fetch, and the ServiceWorker download, rather than treating any single network or file artifact as decisive. This approach will help defenders to identify the malicious activity and prevent the attackers from evading detection.

Key points

  • The SourTrade campaign is a unique example of a malvertising operation that uses a legitimate Bun runtime to make victims' browsers build the final Windows executable.
  • The campaign has been operating since late 2024 and has targeted retail traders and cryptocurrency investors across 12 countries in 25 languages.
  • The use of a legitimate Bun runtime to build the final executable makes it difficult for defenders to identify the malicious activity.
  • Defenders should examine the whole chain, from the ad referral and cloaked landing page through the /config request, the secondary-domain runtime fetch, and the ServiceWorker download, rather than treating any single network or file artifact as decisive.
The Upside

The SourTrade campaign highlights the importance of examining the whole chain of events, from the ad referral to the ServiceWorker download. By doing so, defenders can identify the malicious activity and prevent the attackers from evading detection. This approach will help to improve the security of the internet and prevent similar campaigns in the future.

The Downside

The SourTrade campaign also highlights the limitations of traditional security measures. The use of a legitimate Bun runtime to build the final executable makes it difficult for defenders to identify the malicious activity. This approach allows the attackers to evade detection, making it a challenging threat for defenders to identify.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagsmalvertisingmalwarebrowser securitycryptocurrency securitysocial engineeringthreat intelligenceweb securitywindows security

Author

Swati Khandelwal

Intelligence analysis by

Llama

Published

Jul 25, 2026

Source

thehackernews.com

Share

Topics

malvertisingmalwarebrowser securitycryptocurrency securitysocial engineeringthreat intelligenceweb securitywindows security

Related

More from this desk

Jul 25·bleepingcomputer.com

Malicious sites use JavaScript to build malware in browser memory

A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory. The operation has been active since late 2024 and is localized to 25 languages in 12 countries, p…

Jul 25·bleepingcomputer.com

ShinyHunters data leaks fuel $2,000 sextortion email scam

Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. The emails claim to come from ShinyHunters and tell recipients that hackers compromised their devices after o…

Jul 25·thehackernews.com

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patch Available

A critical unauthenticated RCE flaw (CVE-2026-16723) in Alibaba's Fastjson 1.x library is being actively exploited against Spring Boot applications, but no patch is available from the maintainer.

Jul 25·thehackernews.com

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

Phishing campaigns targeting financial institutions have evolved, with attackers now synchronizing their activity with victims in real-time, authenticating against legitimate insurance portals as victims unknowingly complete the login process.