
Criminals have built a fake network of financial trading websites — impersonating platforms like Solana, Luno, and TradingView — designed to deliver malware in a way that slips past most antivirus software. Instead of asking you to download a suspicious file, these sites use JavaScript running inside your browser to quietly stitch the malware together piece by piece in your computer’s memory before dropping it onto your device. Security researchers describe the browser as being turned into “a local assembly pipeline” for the malware, which is why standard virus scans often miss it.
The campaign has been active since late 2024, targeting users across 12 countries in 25 languages, with a heavy focus on the Asia-Pacific region and Latin America. Retail traders and cryptocurrency investors are the primary targets — the fake sites look convincing enough to fool people who click on links in search ads or social media posts.
How to check if you’re affected
Affected products include unofficial installer files for financial trading platforms such as Solana, Luno, and TradingView downloaded from links in ads, social media posts, or sponsored search results rather than from the official company websites. If you recently installed a trading or crypto app after clicking an advertisement or a link shared online, your device may have been exposed. Check your installed programs for any applications you don’t recognise, and run a full scan with your antivirus software.
Going forward, only download financial apps directly from the official company website or your device’s official app store. Treat any trading platform that appears as a paid search result or in a social media ad as suspicious until verified.
