Jupiter is a malware name used for at least three distinct malicious tools in different ecosystems, and the available information does not support collapsing them into a single family. In one usage, Jupiter refers to an infostealer module within the SolarMarker malware platform. In that role, it is used to profile victim systems and harvest account and financial data from browsers as part of broader on-device fraud operations conducted through SolarMarker’s modular framework on Windows systems. In another usage, JUPITER.32 and JUPITER.64 are browser web-inject components associated with KBOT, a Windows file-infecting banking malware family that steals credentials, payment-card data, wallet information, and other browser-entered data by manipulating web traffic inside supported browsers. In a third usage, Jupiter is listed among custom remote-access tools associated with the DPRK-linked Andariel threat actor, but the supplied facts do not provide enough technical detail to characterize that implant beyond its inclusion in the group’s malware set. Because these references point to different malware contexts with different functions, Jupiter should be treated as an ambiguous malware name rather than a single well-defined family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Over the last 15 years, the group has developed RATs, including the following... ▪ Jupiter
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian-speaking PC trojan listed in the report.
SolarMarker module used for infostealing and device profiling to help attackers understand what accounts and data would be accessible from the victim host.
A DLL-based web-inject component used by KBOT to patch browser and system traffic-handling functions in order to steal credentials, payment card data, wallet numbers, and other personal information entered into browsers.
RAT used for remote access/manipulation and lateral movement.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.