Jupyter is a .NET-based infostealer that targets browser-stored data, particularly from Chromium-family browsers and Firefox, and has also been observed with broader backdoor functionality. Its theft capabilities include collection of personal information, saved credentials, and browser form-submission data. Reported variants and associated modules have also supported command execution, PowerShell execution, download-and-execute of additional payloads, and in some cases process hollowing or similar in-memory execution techniques, indicating post-compromise utility beyond simple credential theft.
Observed infection chains have used multi-stage delivery and in-memory loading. Campaigns have distributed Jupyter through installer-based lures, including ZIP-packaged fake or impersonated software installers and oversized MSI packages used to evade scanning and launch PowerShell during installation. Decoy applications have been used to distract victims while the malicious chain proceeds. The loader has been observed writing encoded payload material into user-profile locations, decoding it, reflectively loading a .NET assembly, and executing the final module in memory.
Persistence mechanisms associated with Jupyter activity have included registry-based autorun persistence, Startup-folder shortcuts, and persistence modules in the loader. The malware has been linked to command-and-control communication over HTTP POST and supports staged execution through a dedicated loader component. Jupyter has also been described as a secondary payload within Solarmarker activity, where it functions as the information-stealing module alongside other Solarmarker components such as updated stagers and a separate keylogging module.
Jupyter activity has affected organizations including higher education and has also appeared in broader opportunistic credential-harvesting campaigns. Some reporting has assessed likely Russian nexus indicators for parts of the operation, but attribution remains limited and should be treated cautiously. The malware is notable for low detection rates during parts of its activity and for combining browser-focused credential theft with flexible backdoor-style execution and persistence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
By using this tool, threat actors gain access to the easy implementation of obscured script executions.
Create_Registry_Key -reg_path (“<REG_PATH”) -execution_command ('Powershell -WindowStyle Hidden -ep Bypass -Command " + $decode_and_execute_payload_script'); ... $lnk_object = New-Object -ComObject WScript.Shell.CreateShortcut($ENV:APPDATA + '<Startup_Lnk_Path');
These include: ... hollowing shellcode into legitimate windows configuration applications.
Create_Registry_Key -reg_path (“<REG_PATH”) -execution_command ('Powershell -WindowStyle Hidden -ep Bypass -Command " + $decode_and_execute_payload_script'); ... $lnk_object = New-Object -ComObject WScript.Shell.CreateShortcut($ENV:APPDATA + '<Startup_Lnk_Path');
This allows the payload to thwart online AV scanners... the Jupyter PowerShell loader... keeps a very evasive file with low to 0 detections on VirusTotal... all of the .NET DLL Payloads should be obfuscated.
These include: ... hollowing shellcode into legitimate windows configuration applications.
The actor now uses a 16 byte, randomly generated AES symmetric key to encrypt the data sent to and from the C2 host... This key is sent with the victim identification string back to the actor's C2 in the first HTTP request, which is itself encrypted using an RSA asymmetric key pair.
These include: a C2 client download and execute malware execution of PowerShell scripts and commands
74 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A .NET infostealer with backdoor capabilities that steals browser data, uses a PowerShell loader and reflective DLL loading, maintains persistence via registry keys and startup shortcuts, and is described as highly evasive with very low detection rates.
A .NET infostealer that steals browser data, primarily from Chromium, Firefox, and Chrome. Its framework also includes loader and backdoor capabilities, including C2 communications, downloading and executing malware, running PowerShell scripts and commands, process hollowing into legitimate Windows configuration applications, and recently added persistence modules.
Highly evasive and adaptive .NET infostealer delivered via SEO poisoning and watering-hole style lures; targets browser data and also provides full backdoor functionality.
A Solarmarker secondary information-stealing module that steals browser credentials, personal information, cookies, and form data from Firefox and Chrome, then exfiltrates the data to C2 over HTTP POST using .NET ProtectedData-based encryption.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.