The United States has reignited tensions in the Middle East by reimposing a naval blockade on Iranian ports.
Malicious Websites Use JavaScript to Build Malware Directly in Browser Memory, Targeting Crypto Investors Worldwide

The campaign, which has reportedly been active since late 2024, employs fake versions of popular cryptocurrency and financial platforms, including Solana, Luno, and TradingView, to lure unsuspecting users into downloading malware. Rather than delivering a conventional malicious executable immediately, the attackers rely on advanced JavaScript techniques that reconstruct the malware entirely within the browser’s memory.
Malware Built in Memory
Unlike traditional malware attacks that download executable files directly onto a victim’s computer, this operation leverages JavaScript running inside the web browser to piece together malicious code in memory. This “fileless” approach significantly reduces the chances of detection by security software, as fewer suspicious files are written to the hard drive.
Once the malware has been assembled in memory, it can be executed to compromise the victim’s device, potentially stealing sensitive information such as cryptocurrency wallet credentials, browser cookies, authentication tokens, passwords, and financial account details.
Cybersecurity experts warn that this technique represents an evolution in browser-based attacks, making it increasingly difficult for conventional endpoint protection solutions to identify malicious activity.
Fake Cryptocurrency and Trading Platforms
The attackers created convincing replicas of legitimate cryptocurrency and financial websites, including fake versions of:
- Solana
- Luno
- TradingView
These counterfeit websites closely imitate the appearance and functionality of the legitimate platforms, encouraging visitors to download supposed trading tools, software updates, browser extensions, or investment applications. Instead, victims unknowingly trigger the browser-based malware delivery process.
Researchers note that the websites are professionally designed, making it difficult for inexperienced users to distinguish them from the authentic services.
Campaign Targets 12 Countries in 25 Languages
According to researchers, the operation has expanded globally and currently supports 25 different languages across 12 countries, with most of its victims located in the Asia-Pacific region and Latin America.
By localizing fake websites into multiple languages, the threat actors increase their credibility and improve the likelihood that users will trust the fraudulent pages.
Security analysts believe the campaign specifically targets retail investors, cryptocurrency traders, and individuals actively participating in online financial markets.
Intelligent Filtering System Avoids Detection
One of the most sophisticated aspects of the campaign is its advanced filtering mechanism.
Before delivering malicious content, the attackers analyze each visitor to determine whether they are a legitimate target. Factors such as browser behavior, device characteristics, IP reputation, language settings, and browsing patterns are used to distinguish genuine users from cybersecurity researchers, automated scanners, and security bots.
If the visitor appears to be a researcher or automated detection system, the malicious website serves only a blank page or harmless content. This selective targeting significantly complicates efforts to investigate and disrupt the operation.
Researchers say this anti-analysis technique has helped the campaign remain active for months while avoiding widespread detection.
Risks for Cryptocurrency Investors
Cybersecurity experts warn that cryptocurrency investors remain among the most attractive targets for cybercriminals due to the irreversible nature of blockchain transactions and the high value of digital assets.
Compromised systems may expose:
- Cryptocurrency wallet seed phrases
- Private keys
- Exchange login credentials
- Browser cookies and authentication sessions
- Passwords saved in web browsers
- Personal financial information
Once attackers gain access to these assets, stolen cryptocurrency is often transferred rapidly through multiple wallets, making recovery extremely difficult.
Security Recommendations
Experts recommend that users take several precautions to reduce the risk of compromise:
- Access cryptocurrency exchanges and trading platforms only through official websites.
- Avoid clicking sponsored advertisements promoting trading software or crypto wallets.
- Verify website URLs carefully before entering login credentials.
- Enable multi-factor authentication (MFA) on all financial accounts.
- Keep browsers and operating systems fully updated.
- Use reputable endpoint security solutions capable of detecting browser-based threats.
- Never download software or browser extensions from unofficial sources.
Growing Threat Landscape
The discovery highlights how cybercriminals continue to evolve their techniques by exploiting legitimate browser technologies. By assembling malware entirely in memory and employing sophisticated visitor filtering, attackers are making detection and investigation increasingly challenging.
Security researchers warn that similar browser-based malware campaigns are likely to become more common as threat actors seek new methods to bypass traditional security defenses and target the rapidly growing global cryptocurrency community.









