Solar is a Windows backdoor associated with the Iranian cyber-espionage actor OilRig, particularly the Lyceum subgroup, and was used in operations targeting organizations in Israel. It is linked to the Outer Space campaign and preceded the later Mango backdoor, which was developed as an improvement over Solar during the Juicy Mix activity cluster. Reported targeting includes sectors such as local government and healthcare, consistent with long-running regional espionage objectives.
Solar supports command-and-control communications with encoded and compressed traffic, including Base64 encoding and gzip compression of command output. It can automatically exfiltrate files from compromised systems and send staged files back to operators. For persistence, Solar creates scheduled tasks named to run at short recurring intervals in order to maintain command-and-control and support exfiltration. Operational reporting also indicates use of compromised infrastructure in the target region to relay communications, including a compromised Israeli human-resources website.
Solar forms part of a broader OilRig tool ecosystem that has included other backdoors and cloud-enabled implants. Available reporting supports classifying Solar as a backdoor used for post-compromise espionage, persistence, and data theft on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Use of compromised infrastructure belonging to entities in regions it targets, as observed in Solar and Veaty malware
Major tools we attribute to Lyceum include ... Solar and Mango ...
11 distinct techniques documented for this family, organized by ATT&CK tactic.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
The content repeatedly describes adversaries and malware deleting files, directories, droppers, scripts, logs, archives, staged data, and other artifacts from compromised systems, e.g., 'APT29 has used SDelete to remove artifacts from victim networks' and 'Lazarus Group malware has deleted files in various ways, including "suicide scripts" to delete malware binaries from the victim.' | Several entries explicitly state files were deleted after exfiltration or upload, such as 'AppleSeed can delete files from a compromised host after they are exfiltrated,' 'Attor’s plugin deletes the collected files and log files after exfiltration,' and 'Ursnif has deleted data staged in tmp files after exfiltration.'
The content repeatedly describes malware and threat actors collecting host details such as OS version, hostname, architecture, CPU, memory, BIOS, domain, language, and other configuration data; e.g., "APT41 uses multiple built-in commands such as systeminfo and net config Workstation to enumerate victim system basic configuration information."
Some Backdoor.Oldrea samples use standard Base64 + bzip2... gh0st RAT has used Zlib to compress C2 communications data before encrypting it... HOPLIGHT has utilized Zlib compression to obfuscate the communications payload.
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as comparative malware associated with use of compromised regional infrastructure.
Malware cited as prior OilRig tooling that used compromised regional infrastructure for communications.
Named backdoor listed among malware/tools, without substantive discussion in this reference.
Malware referenced as using compromised regional infrastructure for communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.