SolarMarker, also known as Jupyter, Polazert, and Yellow Cockatoo, is a modular Windows malware family first observed in 2020. It combines a .NET backdoor with information-stealing, keylogging, form-grabbing, cryptocurrency-wallet theft, remote-control, and proxy capabilities. SolarMarker commonly uses search-engine optimization poisoning, deceptive document- or software-themed landing pages, and signed oversized installers disguised as document downloads to induce user execution. Installers often run legitimate decoy software while deploying the malware.
SolarMarker establishes user-level persistence through a Startup-folder shortcut and a malicious custom file-association handler that invokes PowerShell to decrypt and reflectively load an in-memory .NET payload. It employs obfuscation, encoded and encrypted payloads, random names and decoy files, code-signing certificates, and oversized executable content to hinder detection and automated analysis. Its backdoor communicates over encrypted HTTP, fingerprints infected hosts, accepts PowerShell commands, transfers or loads additional payloads, and supports remote access. Observed variants can steal browser credentials, cookies, autofill data, saved payment-card data, VPN and remote-desktop configurations, and cryptocurrency-wallet data. Operators have also used remote-control functionality to access active browser sessions directly on victim devices for account takeover and financial fraud. Campaigns have broadly targeted users and organizations, including business and financial-sector personnel, rather than a narrowly defined industry vertical. SolarMarker infrastructure was reported to have become inactive in 2024.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ERYTHRITE has technical overlaps to another group multiple IT security organizations have labeled as Solarmarker.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
Certificates are acquired through the following process: An impostor chooses a business to impersonate. They can pass the first stage of certificate validation process if the business is in a government database. They register a related domain which they will use for domain validation.
SolarMarker targets many environments across verticals and sectors... the majority of SolarMarker attacks being delivered from compromised WordPress sites... When the user clicks on the download link, they are redirected... ending up on a fake Google Drive download page.
While TRU has observed SolarMarker executing similar PowerShell commands as Morphisec discussed, the latest analysis shows that the threat actors behind SolarMarker have changed their PowerShell commands again.
TRU has observed SolarMarker executing similar PowerShell commands... SolarMarker attempts to load the Jupyter PowerShell loader from the – scriptFile parameter.
the script uses “CMD /c” to execute a PowerShell command with the Window option of “hidden”.
Overview: Mars-Deimos-RS-2 is .NET binary injected into memory... As mentioned above, the binary is injected into memory by the script and is not written to file.
Evasive techniques such as large payload sizes, obfuscated payload modules and stolen certificates present challenges to antivirus solutions... The updated Mars module also obfuscates its C# code, further hindering analysis efforts.
Instead of a document, they are presented with a malicious executable (.exe) or Microsoft Installer (.msi) file... When file extensions are hidden, SolarMarker appears in file explorer as a PDF
Overview: Mars-Deimos-RS-2 is .NET binary injected into memory... As mentioned above, the binary is injected into memory by the script and is not written to file.
the attacker attempts to cover their tracks by clearing the Chrome History manually by navigating to the Chrome History tab and removing items.
It decodes the file using the key and two For-Loops... we appear to be indexing into and manipulating $fileTwo using “-bxor”... So it appears that the variable... is a key for decoding $fileTwo before loading it in line 7.
SolarMarker Authors Use MSI Files to Evade Detection from AV and Sandboxes... antivirus engines and sandboxes are better equipped to analyze EXE files than MSI files.
Using this Windows API, the malware can make sure the PowerShell or current window stays hidden at execution.
Another noteworthy development is the discovery of a keylogging module, Uranus, which abuses .NET architecture to capture user’s keystrokes and relevant metadata.
With the browser data loaded, threat actors can access accounts to perform financial fraud and data theft.
SolarMarker is a .NET-based backdoor malware designed to steal data, including credentials (e.g. banking, email, IT admin, etc.) and capturing keystrokes.
The Executable then dropped two files: one a .bat script and the other an unreadable file without an extension.
this blog-post discloses—for the first time—the financial fraud carried out by the SolarMarker actor group. In this blog-post, we will introduce SolarMarker—highlighting the Virtual Network Computing (VNC) component which allows threat actors to connect to a victim device and load the victim’s browser data as their own.
194 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a malware family previously distributed through the same likely malvertising/SEO-poisoning technique.
SEO-poisoning backdoor with infostealer capability; one sample was found carrying a HuggingFace API key.
SolarMarker is discussed as a malware family abusing code-signing certificates to sign malicious files, with operators repeatedly obtaining new certificates after revocation.
Mentioned only as a malware family sharing some strings with YASS.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.