Your browser is being used to build a virus. Online ads have become increasingly popular with hackers trying to break into your PC. But a newly discovered campaign takes this threat to a whole new level.
A hacking campaign titled SourTrade has been running quietly in the digital background since late 2024, and it has been targeting people involved in cryptocurrency. Regardless of whether a user is a seasoned cryptocurrency pro or someone dabbling in Bitcoin for the first time, SourTrade has considered them fair game.
Disguising itself on popular platforms like TradingView and Solana, SourTrade has been placing convincing fake ads all across the internet. Click on just one of these ads and you’ll find yourself on what appears to be a trustworthy website. In the background, however, something altogether different is happening.
How Your Browser Becomes the Builder
Most malware campaigns start by sending an infected file to your PC. Usually, these are swiftly dealt with by security software, which can scan and flag any new file entering your PC. The problem with SourTrade is that it does something different. Rather than sending a complete file which is ready to be unleashed, it delivers the malware in small individual fragments. On their own, they’re unlikely to be flagged as dangerous. But when they’re compiled together, it’s a different story.
This building job, surprisingly, is done by the victim’s browser. It does this by using background processes built into browsers to improve performance and manage downloads. These tools are hijacked by the attackers to download the chunks of malicious code, reassemble them, and then let the finished file loose on your PC. To help strengthen this campaign, each victim receives a slightly different version of the final file, making it impossible to flag a specific example as a threat.
Once active, SourTrade is believed to function as a stealer, harvesting saved passwords, browser cookies, and cryptocurrency wallet credentials while potentially giving the attackers remote access to your PC. Therefore, for anyone involved in crypto trading, that means your funds could be at serious risk.
The malicious file is built around a legitimate piece of software called Bun, a genuine tool used by developers and one with a good reputation. Therefore, this helps to disguise it even further from security scans. Consequently, SourTrade is a major threat to all PC users as it’s sophisticated, powerful, and, of course, exceptionally sneaky.
Protecting Your PCs from Malicious Adverts
At present, there’s no software patch to protect you from the threat of SourTrade. Additionally, Google has reported that, in 2025, they had to block or remove over 8.3 billion bad ads, Accordingly, you need to tread carefully online and strengthen your own security habits. To help you reduce your risk, Ophtek recommends these three tips:
- Only download from official sources: online ads, even convincing ones, should never be your first port of call for downloading software. Instead, always head straight to the developer’s official website to ensure your download is as safe as possible.
- Use an ad blocker: attacks such as SourTrade rely on victims seeing their malicious ads, so it’s important that you avoid them. The best way to do this is with an ad blocker that prevents them being loaded.
- Keep your security software updated: always install updates for your security software as soon as possible to keep it up to date. Also, consider using antivirus software which also monitors browser behavior rather than just scanning downloads.
For more ways to secure and optimize your business technology, contact your local IT professionals.




