Plan
archived
Malvertising campaign assembles malware in browser memory via JS
- Engineer — Learn: This technique—assembling malware entirely within browser memory via JavaScript—bypasses file-based detection and signals a shift in delivery model worth factoring into client-side defense strategies (CSP hardening, browser isolation). No specific software to patch; no KEV or PoC signals.
- SOC/IR — Plan: The campaign is described as large-scale and targets users of crypto/trading sites; build or tune EDR behavioral rules for in-browser memory injection and anomalous JS execution patterns this quarter. The summary provides no specific IOCs to hunt on immediately.
- Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.