A new malvertising operation named SourTrade is making the rounds, and it shows how ads can become a portal for malware even when you’re just browsing your usual sites. Here’s what you need to know and how to protect yourself.
What happened
Security researchers from Confiant reported a malvertising campaign dubbed SourTrade. The attackers use legitimate-looking ads to prompt a user to download a final Windows executable, which is built at runtime using the Bun runtime rather than delivering a fixed malicious file from a single URL. The campaign has targeted retail traders and cryptocurrency investors across 12 countries in 25 languages, and it has impersonated recognizable brands such as TradingView, Solana, and Luno to lure victims.
The key takeaway is not just the payload, but the delivery method: compromised ads that try to bypass simple warnings by presenting a convincing, brand-aligned prompt. If a user clicks through and follows the prompt to install what looks like legitimate software, they could be introducing malware onto their device.
Why it matters
- For individuals: You can’t rely on brand familiarity alone. Malvertising can slip past casual scrutiny, especially when the prompt mimics a service you trust.
- For small businesses: Ad networks and employee devices can become a gateway for malware if browsing security isn’t layered with endpoint protections and network filters.
- For creators and IT-minded readers: This campaign illustrates how attackers leverage runtime environments (like Bun) to generate payloads dynamically, complicating static detection.
What you can do now
- Keep software up to date: Ensure your browser, extensions, and security tools are on the latest versions. Patches often include protection against malvertising techniques.
- Use reputable ad-blocking and anti-malvertising tools: Consider extensions or DNS-level protections that filter suspicious ads and trackers.
- Verify download sources: If you’re prompted to download software, verify the vendor’s official site and avoid downloads from ad banners or third-party pages.
- Enable multilayered security: Use endpoint protection, browser sandboxing, and network-level filters to reduce the chance a malicious download executes.
- Educate and test awareness: Regular security awareness for yourself or your team can reduce clicks on deceptive prompts. Treat new download prompts with caution, especially when they’re tied to financial or crypto services.
- For small businesses: Consider implementing network-wide ad filtering and endpoint controls, plus a simple incident response plan in case a device encounters suspected malware.
Final thought
Malvertising continues to evolve, using believable branding and runtime payloads to complicate detection. By staying skeptical of unsolicited download prompts, keeping software updated, and layering defenses, you reduce the risk of a SourTrade-style intrusion. If you notice suspicious ads or downloads, report them to your IT team or the service involved, and review your device security settings.