Find notable cyber news and cases, enriched with sources, timelines, and signals.

SourTrade malvertising campaign impersonating trading and cryptocurrency brands

Campaign
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

The SourTrade malvertising campaign remains active, using lookalike portals and malicious JavaScript to target retail traders and cryptocurrency investors across 12 countries and 25 languages. It impersonates brands such as Solana, Luno, and TradingView to lure victims from ads on Facebook and Google. The delivery chain shifts malware assembly into the browser, increasing stealth and complicating detection. The activity has continued since late 2024 and overlaps with related JSCeal distribution.

Related Happenings

ClickFix browser-injection crypto-fraud campaign

Campaign
H score19 First: 09.09.2026 16:45 Last: 09.09.2026 16:45 Sources 1

About this happening: The ClickFix operation has shifted into browser-side JavaScript injection, expanding its fraud reach and raising the risk of cryptocurrency theft during live trading s...

BengalSEO SEO poisoning campaign

Campaign
H score12 First: 08.09.2026 11:43 Last: 08.09.2026 11:43 Sources 1

About this happening: The BengalSEO operation now stands out as a long-running SEO poisoning campaign that funnels search users into MayaBot malware delivery and tech support scams. Dis...

JSCeal malware activity

Malware Activity
H score29 First: 07.09.2026 10:53 Last: 07.09.2026 10:53 Sources 1

How related: Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities.

About this happening: JSCeal is a compiled V8 JavaScript malware that now stands out for credential harvesting, session replay, and traffic interception against browser data. The ma...

SourTrade malvertising campaign targeting retail traders and crypto investors

Campaign
H score30 First: 25.07.2026 18:21 Last: 25.07.2026 18:21 Sources 1

About this happening: The SourTrade malvertising campaign targets retail traders and cryptocurrency investors by impersonating TradingView, Solana, and Luno. It operates across 12 countries and 25 lang...

Latest development: 25.07.2026 21:48

On April 30, 2026, the pages in the SourTrade delivery chain loaded StreamSaver.js from the author's GitHub Pages address, showing an earlier streamed-download path that pointed the recorded download source at the library URL.

BlueNoroff ClickFix-style Zoom and Microsoft Teams phishing campaign

Campaign
H score38 First: 24.07.2026 18:12 Last: 24.07.2026 18:12 Sources 1

About this happening: BlueNoroff's ClickFix-style phishing campaign is using typosquatted Zoom and Microsoft Teams domains to deliver malware and steal Telegram sessions from high-value cry...

Timeline

  1. 07.09.2026 10:53 2 articles · 13d ago

    SourTrade uses lookalike trading portals to assemble malware in victims’ browsers

    Campaign Scope Update

    SourTrade malvertising redirects retail traders and cryptocurrency investors from ads on Facebook and Google to lookalike portals impersonating Solana, Luno, and TradingView, where malicious JavaScript directs the browser to build malware in memory instead of downloading a finished payload. The campaign is assessed to have been active since late 2024 across 12 countries and 25 languages, and the activity overlaps with a JSCeal distribution cluster.

    Show sources