Yellow Cockatoo is a malware activity cluster associated with the Jupyter Infostealer and SolarMarker malware family, and with the Deimos implant, a .NET-based remote access trojan used for initial access, persistence, and remote tasking. The malware has been observed under active development with layered obfuscation and anti-analysis measures, including encoded and encrypted staging, runtime-generated variables and paths, and heavily obfuscated .NET components. Observed functionality includes execution of PE files, PowerShell scripts, .NET assemblies, and arbitrary commands, along with encrypted command-and-control communications over HTTP. Yellow Cockatoo activity has been linked to broad, opportunistic distribution rather than narrowly targeted intrusions. Delivery has been associated with SEO poisoning and deceptive browser-update style lures, including fake browser update techniques reported less commonly than with some other malware families. Persistence mechanisms attributed to associated Deimos activity include PowerShell-based loaders, registry-handler abuse, Startup-folder shortcut execution, and hiding the core implant among numerous randomly named files. Process injection has also been observed in related telemetry. The cluster is primarily associated with malware delivery, foothold establishment, persistence, and follow-on remote access. While the broader malware family has information-stealing lineage through Jupyter Infostealer, not all observed Yellow Cockatoo-linked samples performed credential or data theft; some functioned primarily as access and persistence implants. Known aliases and closely associated names include SolarMarker and Jupyter Infostealer.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named threat that has used fake browser update techniques, though less commonly.
Uses fake browser update lures (less commonly, per the source) as an initial access vector.
An activity group operating campaigns that use the Deimos implant for initial access, persistence, and command-and-control, with only some samples retaining information-stealing capability. The group is actively modifying its codebase to evade detection and uses SEO poisoning and Google Sneaky Redirects to lure victims into executing signed malware installers.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.