Malvertising Campaign Forces Browsers to Build Executable Malware

A malvertising operation called SourTrade is making victims' browsers build the final Windows executable themselves. instead of serving one complete malicious file from a fixed URL. The campaign has operated since 2024 and impersonated companies like TradingView, Solana, and Luno to target retail traders and cryptocurrency investors across 12 countries. Since the fully assembled malware doesn't exist on the internet, it evades detectors and blocks. To defend against this evolving threat, users must strictly avoid downloading software from ads and visit official vendor websites directly.