Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Stage 1 : La landing page enregistre un ServiceWorker (sw.js) et instancie un SharedWorker depuis un blob JavaScript embarqué dans le code React de la page.
Le SharedWorker interroge /config et reçoit des instructions d’assemblage... un tableau template, une graine AES-CTR aléatoire par session... le navigateur ... combine ces éléments avec des blobs base64 ... pour assembler l’exécutable final en mémoire.
Users are presented with websites that appear legitimate that offer software downloads by impersonating popular platforms such as Solana, Luno, and TradingView.
Browsers download legitimate Bun runtimes from a secondary domain as part of the assembly process, and they combine them with attacker-controlled executable components and locally generated data as part of the assembly process.
101 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malvertising campaign that impersonates TradingView, Solana, and Luno and delivers malware by having the victim’s browser locally assemble a Windows executable from separate components using the legitimate Bun runtime, ServiceWorker, and SharedWorker logic. The final payload was not analyzed and remains unknown.
SourTrade is a persistent malvertising operation that targets cryptocurrency investors and retail traders with spoofed ads and landing pages. Its key technique is browser-assembled malware: components and instructions are delivered separately, then combined in the victim’s browser into a final executable in memory, enabling per-victim uniqueness and evasion of file-hash and network-based detection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.