SourTrade, an active malvertising campaign since late 2024, deploys a fragmented delivery method to evade detection and block lists. Rather than serving a complete malware executable, the operation distributes malicious code in pieces across multiple ad network requests. The victim's browser then assembles these fragments into a working Windows executable using the Bun JavaScript runtime as a base.

Confiant researchers identified the technique on July 23, 2026. The campaign impersonates legitimate financial platforms including TradingView, Solana, and Luno to target retail traders specifically. By fragmenting payloads, SourTrade bypasses traditional URL reputation checks and signature-based detection systems that flag known malware distributions.

The tactic offers operators several advantages. Each fragment appears benign in isolation, reducing the likelihood of triggering security scanners. The use of Bun, a legitimate and often-trusted runtime environment, provides cover that standard endpoint detection systems may overlook. Multiple requests from different ad network sources complicate attribution and blocking. Traders visiting compromised ad networks or legitimate sites displaying malicious ads face infection without downloading anything directly.

This approach reflects evolving malware distribution strategies. Rather than relying on single points of compromise, attackers now distribute responsibility across infrastructure to survive network defenses and browser-based protections. The targeting of financial traders makes sense, as this demographic typically handles sensitive accounts and possesses valuable assets.

Organizations and individuals should implement strict ad blocker policies, particularly on trading platforms where credential theft and account compromise carry direct financial consequences. Browser isolation solutions offer strong protection against this class of attack. Financial institutions should educate customers about ad-based infection vectors and recommend disabling JavaScript execution on untrusted networks.

The SourTrade campaign demonstrates how malware delivery continues to evolve beyond signature-based defenses. Security teams monitoring trading platform access should watch for