Affected Systems
Users of Solana, Luno, and TradingView platforms targeted via malicious advertisements. Campaign uses fake webpages that deliver JavaScript-based malware assembled directly in browser memory, affecting users across all platforms and browsers.
Exploitation Status
Active exploitation confirmed. Large-scale malvertising campaign currently operational, using in-memory malware assembly techniques to evade traditional antivirus and endpoint detection.
Business Impact
High risk to organizations with cryptocurrency trading operations or users accessing these platforms. In-memory assembly bypasses signature-based detection, making traditional AV ineffective. Potential for credential theft, session hijacking, and financial fraud. SOC teams may lack visibility into infections as malware never touches disk. User education and network-level controls are critical.
Urgency
🟠Within 24 hours
Recommended Actions
- Block known malicious domains associated with fake Solana, Luno, and TradingView sites at DNS and web proxy level
- Deploy browser isolation technology or enforce strict content security policies to limit JavaScript execution from untrusted sources
- Monitor network traffic for connections to legitimate cryptocurrency platforms and flag anomalous domains with similar naming patterns
- Educate users to verify URLs carefully before entering credentials, emphasizing official domains for Solana, Luno, and TradingView
- Enable advanced endpoint detection with behavior-based monitoring capable of detecting fileless/in-memory malware execution
