logo

Mars-Deimos: SolarMarker/Jupyter Infostealer (Part 1)

ID: 9363ba00-52d1-5ce7-a89d-d457058e71be

STIX ID: report--9363ba00-52d1-5ce7-a89d-d457058e71be

Feed Name: Binary Defense Blog

Threat Score
70/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

This report analyzes the persistence stage of the Mars-Deimos backdoor (also documented as Solarmarker/Jupyter), deobfuscating a PowerShell script that decodes a second file, XOR-decrypts it, loads a .NET assembly into memory, and uses modified desktop shortcuts for persistence; dynamic analysis revealed creation of a static artifact (solarmarker.dat) useful for detection and remediation. The author documents methods to extract the in-memory binary to disk for static analysis, demonstrates dynamic triage using Sysinternals, and highlights detection gaps and recommended response actions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.