← Home
CYBERSECURITY

Malvertising Campaign Uses Browsers to Build Malware

August 1, 2026 Daniel Cross

Evading Detection with Legitimate Tools

A malvertising operation known as SourTrade is tricking victims' browsers into constructing Windows executables, rather than downloading a single malicious file. This campaign was detailed on July 23, 2026. The attackers are using a legitimate Bun runtime as the foundation.

The malvertising operation is notable for its innovative approach. Instead of serving a complete malicious file from a fixed URL, the attackers are sending malware in pieces. The browser then assembles these pieces into a final executable. This technique allows the attackers to evade traditional security measures.

The attackers are leveraging the legitimate Bun runtime to build the malicious executable. This approach makes it more challenging for security software to detect the malware, as it is being constructed by a trusted tool. The use of Bun runtime also suggests that the attackers are adapting to the evolving security landscape.

Can Security Measures Keep Up?

The campaign's details were revealed by Confiant, which has been tracking the operation. By using a legitimate tool to build the malware, the attackers are able to stay under the radar.

As security measures continue to evolve, attackers are finding new ways to evade detection. The SourTrade campaign highlights the need for continued innovation in security measures.

The consequences of this campaign could be significant, as it has the potential to compromise a large number of browsers. As the attackers continue to adapt and evolve, it is likely that we will see further innovations in malvertising campaigns.

Frequently Asked Questions

What is the SourTrade malvertising campaign? The SourTrade campaign is a malvertising operation that tricks victims' browsers into building Windows executables.

How does the campaign evade detection? The campaign evades detection by using a legitimate Bun runtime to build the malicious executable, making it harder for security software to identify the malware.

What are the potential consequences of this campaign? The campaign has the potential to compromise a large number of browsers, highlighting the need for continued innovation in security measures.

Read full article on Tech Site News →