logo

Solarmarker: By Any Other Name (Mars-Deimos part 3)

ID: 2d9ea6dc-281e-56aa-8c7a-da0eef72e7bd

STIX ID: report--2d9ea6dc-281e-56aa-8c7a-da0eef72e7bd

Feed Name: Binary Defense Blog

Threat Score
75/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

Solarmarker (also known as JupyterInfostealer/YellowCockatoo) is an actively evolving infostealer/backdoor campaign; this report catalogs recent changes in persistence, obfuscation, packaging (shift from .exe to .msi), hardcoded C2s (including ASN trends), sample SHA256s, and provides detection guidance (YARA rule, registry and network hunting queries) and distribution observations (Freenom domains, Blogspot).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.