Security researchers reported the emergence of Win32/Napolar—also marketed by its author as solarbot—as a new bot malware family used in the wild for credential theft, DDoS, SOCKS proxying, and remote payload execution. The malware was observed infecting victims primarily in South America, with notable concentrations in Peru, Ecuador, and Colombia, and it communicated with command-and-control servers over HTTP while encrypting commands with RC4 keyed to the bot identifier.
Analysis showed Napolar included advanced anti-analysis and evasion techniques uncommon for a newly surfaced crimeware family, including staged TLS decryption, runtime API resolution by hash, use of undocumented NTDLL functions, position-independent code, and self-debugging through code injection into a child process. Researchers also found browser-hooking capabilities for web-form theft and logic to detect and terminate processes containing trusteer, indicating attempts to bypass banking-browser protections; meanwhile, the malware was openly advertised online with builds reportedly sold for $200, along with changelogs, C2 server code, and plugin examples that pointed to a professionalized malware-for-sale operation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
By mid-August, the malware had come to researchers’ attention because of its anti-debugging and code-injection techniques. ESET identified the family as Win32/Napolar and documented its HTTP-based C2, credential theft, SOCKS proxy, DDoS, and anti-analysis features.
Win32/Napolar was observed infecting systems in the wild starting in mid-August. Reports indicated thousands of infections, many concentrated in South America, especially Peru, Ecuador, and Colombia.
Researchers reported that the Win32/Napolar malware family became active at the end of July. The malware was marketed by its author as "solarbot" and offered multiple criminal capabilities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.