Solar

MITRE ATT&CK: S1166 View on attack.mitre.org

Aliases: Solar

First seen
2017-05-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
windows
Related IoCs
158 (80 malicious)
Last IoC activity
2026-09-02 00:39:50
Profile updated
2026-07-07 15:11:09

Targeted industries: government-and-public-sector energy-and-utilities

Targeted regions: country_code:il country_code:sa country_code:us

Context

Solar is a C#/.NET backdoor that was used by OilRig during the Outer Space campaign to download, execute, and exfiltrate files.

Recent IoC activity

81 malicious indicators in Maltiverse are attributed to Solar (S1166). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname anonymous-solar.livehost.fr 2026-09-03 1
hostname parentsforliberty.org 2026-09-03 1
hostname j4ckd4w.ugu.pl 2026-09-02 1
hostname mrflom03botnet.hostingsiteforfree.com 2026-09-02 1
hostname bagmar.com 2026-09-02 1
hostname xram.onlinewebshop.net 2026-09-02 1
URL http://proforum.uboxi.com/index.php?login 2026-09-02 1
hostname kommanderkakadu.bplaced.net 2026-09-02 2
hostname botnet.livehost.fr 2026-09-02 1
hostname nouveau-site-message.livehost.fr 2026-09-02 1
hostname david5110.livehost.fr 2026-09-02 1
hostname cakerycafe.com 2026-09-02 1
URL http://black.br22.net/castelo/Panel/index.php?login 2026-09-01 1
URL http://www.anonymousbot.altervista.org/index.php?login 2026-09-01 1
URL http://botnett.bl.ee/Panel/?login 2026-08-31 1
URL http://timeteam.altervista.org/solar/index.php?login 2026-08-31 1
URL http://188.209.52.80/Panel/index.php?login 2026-08-30 1
URL http://www.minisolarbot.altervista.org/index.php?login 2026-08-27 1
URL http://boosting-service.www7.site/?login 2026-08-26 1
URL http://viethoc.com/themes/index.php?login 2026-08-26 1

Detection coverage

  • 159 Sigma rules

Malware & tools used

  • Scheduled Task (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Automated Exfiltration (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • System Information Discovery (attack-pattern)
  • File Deletion (attack-pattern)
  • Standard Encoding (attack-pattern)

Used by threat actors

  • OilRig (threat-actor)
  • Outer Space (campaign)
  • SolarWinds Compromise (campaign)

Reports & references

  • ESET — Oilrigs Outer Space Juicy Mix Same Ol Rig New Drill Pipes (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Solar (report)
  • MITRE ATT&CK — S1166 (report)

External references