solarmarker

Aliases: Jupyter, Polazert, Yellow Cockatoo

First seen
2020-04-01 00:00:00
Malware type
backdoor, credential-stealer, trojan
Family
Malware family
Last IoC activity
2026-07-17 23:15:45
Profile updated
2026-07-07 14:27:31

Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications education-and-nonprofits

Context

Unit 42 notes that they identified a new version of SolarMarker, a malware family known for its infostealing and backdoor capabilities, mainly delivered through search engine optimization (SEO) manipulation to convince users to download malicious documents. Some of SolarMarker’s capabilities include the exfiltration of auto-fill data, saved passwords and saved credit card information from victims’ web browsers. Besides capabilities typical for infostealers, SolarMarker has additional capabilities such as file transfer and execution of commands received from a C2 server. The malware invests significant effort into defense evasion, which consists of techniques like signed files, huge files, impersonation of legitimate software installations and obfuscated PowerShell scripts.

Detection coverage

  • 12 YARA rules

Detection rules

  • ARKBIRD_SOLG_MAL_Polazert_Apr_2021_1 (yara-rule)
  • RUSSIANPANDA_Solarmarker_Loader_PS2EXE (yara-rule)
  • RUSSIANPANDA_Solardropper (yara-rule)
  • RUSSIANPANDA_Solarmarker_First_Stage_Payload (yara-rule)
  • RUSSIANPANDA_Solarmarker_Loader (yara-rule)
  • BLACKBERRY_Mal_Infostealer_EXE_Jupyter_Cert_36Ff (yara-rule)
  • BLACKBERRY_Mal_Infostealer_Win32_Jupyter_Download_And_Execute_Module (yara-rule)
  • BLACKBERRY_Mal_Infostealer_Win32_Jupyter_Main_Module (yara-rule)
  • EMBEERESEARCH_Win_Solarmarker_Stage2_Bytecodes_Dec_2023 (yara-rule)
  • EMBEERESEARCH_Win_Solarmarker_Bytecodes (yara-rule)
  • DITEKSHEN_MALWARE_Win_Solarmarker (yara-rule)
  • SEKOIA_Infostealer_Win_Solarmarker_Dll (yara-rule)

Reports & references

  • cisecurity.org — Top 10 Malware March 2022 (report)
  • proofpoint.com — Ta569 Socgholish And Beyond (report)
  • embeeresearch.io — Shodan Censys Queries (report)
  • embee-research.ghost.io — Shodan Censys Queries (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Solarmarker (report)
  • squiblydoo.blog — Solarmarker The Old Is New (report)
  • security5magics.blogspot.com — Tracking Jupyter Malware (report)
  • recordedfuture.com — Exploring The Depths Of Solarmarkers Multi Tiered Infrastructure (report)
  • squiblydoo.blog — Solarmarker Actions On Target (report)
  • Palo Alto Unit 42 — Solarmarker Malware (report)
  • news.sophos.com — Solarmarker Campaign Used Novel Registry Changes To Establish Persistence (report)
  • blogs.vmware.com — Jupyter Rising An Update On Jupyter Infostealer (report)
  • CrowdStrike — Solarmarker Backdoor Technical Analysis (report)
  • esentire.com — Esentire Threat Intelligence Malware Analysis Solarmarker (report)
  • squiblydoo.blog — Mars Deimos From Jupiter To Mars And Back Again Part Two (report)
  • blogs.blackberry.com — Threat Thursday Jupyter Infostealer Is A Master Of Disguise (report)
  • esentire.com — Hackers Flood The Web With 100 000 Malicious Pages Promising Professionals Free Business Forms But Are Delivering Malware Reports Esentire (report)
  • Cisco Talos — Threat Spotlight Solarmarker (report)
  • binarydefense.com — Mars Deimos From Jupiter To Mars And Back Again Part Two (report)
  • binarydefense.com — Mars Deimos Solarmarker Jupyter Infostealer Part 1 (report)
  • blog.morphisec.com — Jupyter Infostealer Backdoor Introduction (report)
  • hunt.io — Solarmarker Hunt Insight And Findings (report)
  • blog.minerva-labs.com — New Iocs Of Jupyter Stealer (report)
  • blog.morphisec.com — New Jupyter Evasive Delivery Through Msi Installer (report)
  • prodaft.com — Solarmarker Tlpwhitev2 (report)

External references