A malvertising chain tied to trading and crypto lures shows how ServiceWorkers and SharedWorkers can be repurposed for runtime assembly inside the browser, complicating file-based defense.
SourTrade turns ordinary web delivery into a per-victim build process, a design that weakens hash-based detection and blurs the line between browsing and infection.
A counterfeit verification flow and a fake Windows crash screen show how modern malware campaigns are shifting the first click from code to psychology, with SmartRAT as the reported payload.