Solar
MITRE ATT&CK: S1166 View on attack.mitre.org
Aliases: Solar
- First seen
- 2017-05-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 158 (80 malicious)
- Last IoC activity
- 2026-09-02 00:39:50
- Profile updated
- 2026-07-07 15:11:09
Targeted industries: government-and-public-sector energy-and-utilities
Targeted regions: country_code:il country_code:sa country_code:us
Context
Solar is a C#/.NET backdoor that was used by OilRig during the Outer Space campaign to download, execute, and exfiltrate files.
Recent IoC activity
81 malicious indicators in Maltiverse are attributed to Solar (S1166). The 20 most recently updated:
Detection coverage
- 159 Sigma rules
Malware & tools used
- Scheduled Task (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Automated Exfiltration (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- System Information Discovery (attack-pattern)
- File Deletion (attack-pattern)
- Standard Encoding (attack-pattern)
Used by threat actors
- OilRig (threat-actor)
- Outer Space (campaign)
- SolarWinds Compromise (campaign)
Reports & references
- ESET — Oilrigs Outer Space Juicy Mix Same Ol Rig New Drill Pipes (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Solar (report)
- MITRE ATT&CK — S1166 (report)