Malvertising hides malware in browser memory via fake finance sites

Websites mimicking Solana, Luno, and TradingView are spreading malware through a large malvertising campaign that tricks browsers into assembling malicious code in memory. Instead of downloading files to disk, the attack runs entirely in RAM, making it harder to detect with traditional antivirus tools.
How the attack works under the hood
The malicious JavaScript on these spoofed pages instructs the browser to build and run malware components directly in memory. By avoiding file writes to the hard drive, the payload remains invisible to many endpoint security products that focus on disk-based threats. Once executed, the in-memory malware can perform actions such as stealing credentials or installing additional threats.
Why fraudsters target finance platforms
Fake pages for Solana, Luno, and TradingView attract users interested in cryptocurrency and trading, increasing the chances that visitors will interact with the malicious scripts. The campaign capitalizes on the trust users place in these platforms to deliver the attack payload without raising immediate suspicion.
Why it matters
This campaign highlights a shift toward fileless malware that operates solely in memory, reducing detection opportunities and complicating incident response. Users should remain cautious about clicking ads or links, especially on finance-related sites, and organizations should review browser-based threat detection strategies to catch in-memory attacks. The rise of such techniques signals a growing challenge for security teams in keeping up with stealthier attack methods.
Source: BleepingComputer. AI-assisted editorial synthesis — TechnoExpress.

