Solarmarker: By Any Other Name (Mars-Deimos part 3)
ID: 2d9ea6dc-281e-56aa-8c7a-da0eef72e7bd
STIX ID: report--2d9ea6dc-281e-56aa-8c7a-da0eef72e7bd
Feed Name: Binary Defense Blog
Threat Score
Solarmarker (also known as JupyterInfostealer/YellowCockatoo) is an actively evolving infostealer/backdoor campaign; this report catalogs recent changes in persistence, obfuscation, packaging (shift from .exe to .msi), hardcoded C2s (including ASN trends), sample SHA256s, and provides detection guidance (YARA rule, registry and network hunting queries) and distribution observations (Freenom domains, Blogspot).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
