solarmarker
Aliases: Jupyter, Polazert, Yellow Cockatoo
- First seen
- 2020-04-01 00:00:00
- Malware type
- backdoor, credential-stealer, trojan
- Family
- Malware family
- Last IoC activity
- 2026-07-17 23:15:45
- Profile updated
- 2026-07-07 14:27:31
Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications education-and-nonprofits
Context
Unit 42 notes that they identified a new version of SolarMarker, a malware family known for its infostealing and backdoor capabilities, mainly delivered through search engine optimization (SEO) manipulation to convince users to download malicious documents. Some of SolarMarker’s capabilities include the exfiltration of auto-fill data, saved passwords and saved credit card information from victims’ web browsers. Besides capabilities typical for infostealers, SolarMarker has additional capabilities such as file transfer and execution of commands received from a C2 server. The malware invests significant effort into defense evasion, which consists of techniques like signed files, huge files, impersonation of legitimate software installations and obfuscated PowerShell scripts.
Detection coverage
- 12 YARA rules
Detection rules
- ARKBIRD_SOLG_MAL_Polazert_Apr_2021_1 (yara-rule)
- RUSSIANPANDA_Solarmarker_Loader_PS2EXE (yara-rule)
- RUSSIANPANDA_Solardropper (yara-rule)
- RUSSIANPANDA_Solarmarker_First_Stage_Payload (yara-rule)
- RUSSIANPANDA_Solarmarker_Loader (yara-rule)
- BLACKBERRY_Mal_Infostealer_EXE_Jupyter_Cert_36Ff (yara-rule)
- BLACKBERRY_Mal_Infostealer_Win32_Jupyter_Download_And_Execute_Module (yara-rule)
- BLACKBERRY_Mal_Infostealer_Win32_Jupyter_Main_Module (yara-rule)
- EMBEERESEARCH_Win_Solarmarker_Stage2_Bytecodes_Dec_2023 (yara-rule)
- EMBEERESEARCH_Win_Solarmarker_Bytecodes (yara-rule)
- DITEKSHEN_MALWARE_Win_Solarmarker (yara-rule)
- SEKOIA_Infostealer_Win_Solarmarker_Dll (yara-rule)
Reports & references
- cisecurity.org — Top 10 Malware March 2022 (report)
- proofpoint.com — Ta569 Socgholish And Beyond (report)
- embeeresearch.io — Shodan Censys Queries (report)
- embee-research.ghost.io — Shodan Censys Queries (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Solarmarker (report)
- squiblydoo.blog — Solarmarker The Old Is New (report)
- security5magics.blogspot.com — Tracking Jupyter Malware (report)
- recordedfuture.com — Exploring The Depths Of Solarmarkers Multi Tiered Infrastructure (report)
- squiblydoo.blog — Solarmarker Actions On Target (report)
- Palo Alto Unit 42 — Solarmarker Malware (report)
- news.sophos.com — Solarmarker Campaign Used Novel Registry Changes To Establish Persistence (report)
- blogs.vmware.com — Jupyter Rising An Update On Jupyter Infostealer (report)
- CrowdStrike — Solarmarker Backdoor Technical Analysis (report)
- esentire.com — Esentire Threat Intelligence Malware Analysis Solarmarker (report)
- squiblydoo.blog — Mars Deimos From Jupiter To Mars And Back Again Part Two (report)
- blogs.blackberry.com — Threat Thursday Jupyter Infostealer Is A Master Of Disguise (report)
- esentire.com — Hackers Flood The Web With 100 000 Malicious Pages Promising Professionals Free Business Forms But Are Delivering Malware Reports Esentire (report)
- Cisco Talos — Threat Spotlight Solarmarker (report)
- binarydefense.com — Mars Deimos From Jupiter To Mars And Back Again Part Two (report)
- binarydefense.com — Mars Deimos Solarmarker Jupyter Infostealer Part 1 (report)
- blog.morphisec.com — Jupyter Infostealer Backdoor Introduction (report)
- hunt.io — Solarmarker Hunt Insight And Findings (report)
- blog.minerva-labs.com — New Iocs Of Jupyter Stealer (report)
- blog.morphisec.com — New Jupyter Evasive Delivery Through Msi Installer (report)
- prodaft.com — Solarmarker Tlpwhitev2 (report)