Solar is a Windows backdoor associated with the Iranian cyberespionage actor OilRig, including activity tracked under the Lyceum subgroup. It was used in operations targeting organizations in Israel, including local government and healthcare entities, and was also linked to an intrusion that leveraged a compromised Israeli human-resources website as command-and-control infrastructure. Solar is part of OilRig’s evolving custom malware ecosystem and was later superseded or improved upon by the Mango backdoor in the Juicy Mix campaign.
Solar supports command-and-control communications with encoding and compression, including Base64 encoding and gzip compression of traffic and command output. It can automatically exfiltrate files from compromised systems and send staged files back to operators. For persistence and operational support, Solar can create scheduled tasks named Earth and Venus that run at short recurring intervals to maintain command-and-control and exfiltration activity.
Available reporting places Solar within OilRig’s broader long-running espionage tradecraft, which emphasizes stealthy persistence, use of compromised infrastructure, and iterative malware development tailored to Middle Eastern targeting. High-confidence reporting supports Solar as a custom backdoor used for espionage-oriented post-compromise access and data theft on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Solar malware communicated through the compromised website of an Israeli human-resources company...
Major tools we attribute to Lyceum include ... Solar and Mango ...
11 distinct techniques documented for this family, organized by ATT&CK tactic.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
The content repeatedly describes adversaries and malware deleting files, directories, droppers, scripts, logs, archives, staged data, and other artifacts from compromised systems, e.g., 'APT29 has used SDelete to remove artifacts from victim networks' and 'Lazarus Group malware has deleted files in various ways, including "suicide scripts" to delete malware binaries from the victim.' | Several entries explicitly state files were deleted after exfiltration or upload, such as 'AppleSeed can delete files from a compromised host after they are exfiltrated,' 'Attor’s plugin deletes the collected files and log files after exfiltration,' and 'Ursnif has deleted data staged in tmp files after exfiltration.'
The content repeatedly describes malware and threat actors collecting host details such as OS version, hostname, architecture, CPU, memory, BIOS, domain, language, and other configuration data; e.g., "APT41 uses multiple built-in commands such as systeminfo and net config Workstation to enumerate victim system basic configuration information."
Some Backdoor.Oldrea samples use standard Base64 + bzip2... gh0st RAT has used Zlib to compress C2 communications data before encrypting it... HOPLIGHT has utilized Zlib compression to obfuscate the communications payload.
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware cited as prior OilRig tooling that used compromised regional infrastructure for communications.
Malware referenced as using compromised regional infrastructure for communications.
A Lyceum/OilRig malware family mentioned as part of the subgroup's toolset using legitimate cloud services for C2 communication.
A novel malware family referenced as used by OilRig.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.