Jupyter Infostealer is a Windows malware family first identified in late 2020 and commonly associated with the Yellow Cockatoo, SolarMarker, Polazert, and Deimos activity cluster. It combines browser-focused information theft with a modular .NET implant architecture. Observed variants harvest browser credentials and cookies from Chrome, Microsoft Edge, and Firefox, enabling credential theft and potential session hijacking, and exfiltrate collected information through encrypted command-and-control communications. Related Deimos implant variants emphasize persistent remote access and arbitrary payload execution rather than information theft.
The malware uses heavily obfuscated PowerShell and .NET reflection to decrypt and load payload assemblies in memory. It employs layered evasion including Base64 encoding, XOR decryption, randomized working directories and decoy files, cleanup of intermediate artifacts, obfuscated runtime variables, and code signing on lure executables. Persistence has been established through user-level file-association hijacking paired with Startup-folder shortcuts; other observed variants modified desktop shortcuts. Remote-access components collect host profiling data, establish HTTP-based encrypted command-and-control, and can execute PowerShell, .NET assemblies, and Windows executables. Some Yellow Cockatoo-associated components additionally use process hollowing for payload execution.
Jupyter Infostealer is primarily distributed through SEO poisoning, search-engine redirect abuse, malicious websites and drive-by downloads, and phishing-themed executables masquerading as documents, PDFs, or software installers. Activity has been observed across multiple sectors, with education and healthcare notably affected in some campaigns. Campaigns have appeared broadly opportunistic rather than narrowly targeted.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The above PowerShell command was executed to decrypt the .DAT file... with a custom XOR key.
it appears that a user downloaded an executable that was disguised as a Word document.
“Elastic observed process injection telemetry that shared techniques with the Jupyter Infostealer.”
These same files then get deleted a few minutes after initial infection.
Connect to, and communicate with, a command and control (C2) domain ... It connects to the C2 server (address: https://gogohid[.]com/gate?q=ENCODED_HOST_INFO ) sharing a variety of host information and retrieving its first command.
72 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An infostealer malware family that targets Chrome, Edge, and Firefox users via SEO poisoning, search-engine redirects, malicious downloads, and fake installers. It harvests credentials, uses encrypted C2 communications to exfiltrate data, leverages signed binaries and PowerShell-based decryption/loading, and can establish persistence while loading payloads in memory via reflective assembly loading.
A malware family previously associated with Deimos; some samples included information-stealing features, but the observed Deimos sample was not leveraged as an information stealer.
An information-stealing malware previously associated with Deimos activity. The analyzed Deimos sample was not used as an infostealer, although 12.5% of observed Deimos samples retained information-stealing features similar to Jupyter.
A directly related malware variant that shares IOCs and some functionality with Mars Deimos, but is maintained independently by the malware authors and can also steal cookies from browsers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.