:

MALVERTISING CAMPAIGN BUILDS MALWARE IN BROWSER MEMORY

DEV DESK1 MIN READ
SAT, JUL 25, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A widespread malvertising operation is deploying malicious JavaScript on fake cryptocurrency and trading sites to assemble malware directly in browser memory, bypassing traditional detection methods.

The campaign uses counterfeit webpages mimicking Solana, Luno, and TradingView to distribute the attack. By constructing malware in memory rather than writing files to disk, the threat actors evade antivirus and security tools that typically scan stored files. This in-memory assembly technique represents an escalation in malvertising tactics. The malicious JavaScript executes when users visit the fake sites, allowing attackers to build and deploy malware without leaving traditional forensic traces. The fake pages appear designed to harvest credentials or deploy financial theft malware targeting cryptocurrency users and traders. Security researchers have documented the campaign targeting users across multiple regions. Users should verify URLs carefully before accessing financial platforms and consider using security browser extensions. Organizations can mitigate risk by implementing content security policies and restricting JavaScript execution on untrusted domains.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

The UK's AISI and CAISI have released a preliminary assessment of Kimi K3's cybersecurity capabilities. The evaluation examines the system's potential vulnerabilities and defensive strengths.

2H AGOAI Desk

The Department of Justice is prosecuting Sam Tunick, a Cop City protester, for allegedly using a duress passcode on his GrapheneOS phone that wiped its contents when presented to Customs and Border Protection agents.

3H AGOIndustry Desk

Threat actors are weaponizing email addresses from ShinyHunters data breaches to launch a coordinated sextortion campaign demanding $2,000 in Bitcoin from targets.

3H AGOAI Desk

A U.S. citizen is asking a court to dismiss government accusations that he used a 'duress' password to erase his phone during a border search, raising fresh constitutional questions about digital privacy rights.

8H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.