Prevent Ransomware Blog

What If Your Browser Builds the Malware for the Attacker?

Written by Tony Chiappetta | Aug 6, 2026, 8:59:59 AM

Could your web browser actually help an attacker build malware on your own computer?

That is essentially what researchers uncovered in a sophisticated malvertising campaign called SourTrade. Instead of sending victims a finished malicious file that security tools can easily inspect and identify, the attackers deliver separate components and instructions that allow the browser to assemble the final executable locally.

That matters because it challenges one of the fundamental assumptions behind traditional malware detection.

So what exactly happened?

According to The Hacker News and security researchers at Confiant, SourTrade has operated since late 2024 and has impersonated legitimate trading and cryptocurrency brands.

Victims encounter malicious advertisements and are directed to convincing imitation websites.

But the unusual part happens next.

Rather than downloading one complete malicious program, the browser retrieves a legitimate Bun software runtime, attacker-controlled components, and assembly instructions. The browser then combines those pieces locally to create the executable.

Each victim can receive a uniquely assembled file with a different hash.

In practical terms, defenders looking only for a known malicious file may never see the same file twice.

Why does this matter to businesses?

Most organizations have spent years improving their ability to detect and respond to malicious software.

Attackers are designing techniques specifically around those defenses.

Modern attacks may use credential abuse, legitimate applications, living-off-the-land techniques, in-memory activity, security-tool tampering, or constantly changing malware to reduce the value of traditional indicators.

The financial consequences remain substantial. IBM's 2025 Cost of a Data Breach Report found the global average cost of a data breach was $4.44 million.

Verizon's 2025 Data Breach Investigations Report found ransomware appeared in 44% of breaches, a 37% increase from the previous year. Credential abuse remained the leading initial access vector at 22%.

Beyond direct financial loss, businesses can face downtime, lost productivity, damaged customer confidence, regulatory exposure, recovery costs, and weeks of operational disruption.

Is Detect and Respond still enough?

Detection remains important, but organizations should assume some attacks will bypass it.

SourTrade illustrates the problem particularly well. There may not be one predictable malicious file moving across the network for a security product to recognize. The final executable can be assembled locally and changed from session to session.

Detection also creates a timing problem. If malicious activity must begin before security software recognizes it, attackers have an opportunity to steal credentials, move laterally, disable defenses, or begin encryption.

Modern ransomware increasingly turns that detection window into business risk.

What is changing in endpoint security?

Businesses should complement Detect and Respond with Isolation and Containment.

The objective is different.

Instead of asking only, "Is this application malicious?" security controls can restrict what applications are allowed to execute and what trusted applications are permitted to do.

That can help prevent unauthorized execution, restrict attacker movement, reduce the blast radius of compromised applications, and stop damaging actions before encryption or credential theft occurs.

AppGuard is a proven endpoint protection solution with a 10-year track record focused on prevention through Isolation and Containment.

It does not replace every security technology. The broader lesson is that prevention controls can complement EDR, MDR, antivirus, and other detection systems by limiting what an attacker can accomplish when detection fails.

What Should Businesses Do Next?

Business leaders should assume that some threats will eventually bypass detection.

Add prevention layers that restrict execution and application actions. Reduce unnecessary endpoint execution freedom. Test what happens when EDR or antivirus fails. Review third-party and administrative access. Segment critical systems. Protect credentials. Maintain tested backups and incident response plans.

Most importantly, evaluate cybersecurity based not only on how quickly an attack can be detected, but on how much damage an attacker can actually cause before detection occurs.

Browser-assembled malware is another reminder that attackers continue changing the delivery mechanism.

Security architecture needs to change with them.

Business owners who want to better understand how prevention-first security can stop attacks before damage occurs should review our August 5th podcast and schedule time to talk with CHIPS about how AppGuard can help prevent incidents like this through Isolation and Containment.