logo

Mars-Deimos: From Jupiter to Mars and Back again (Part Two)

ID: eed12d03-14c0-5050-af24-da2e48d4d933

STIX ID: report--eed12d03-14c0-5050-af24-da2e48d4d933

Feed Name: Binary Defense Blog

Threat Score
75/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

This report analyzes the Mars-Deimos / Jupyter (Solarmarker) malware family and its large-scale distribution campaign: attackers host thousands of malicious Google Sites that redirect victims to spoofed Microsoft/Google Drive pages to download oversized executable droppers (often InnoSetup or Delphi-built) which execute obfuscated PowerShell to load info-stealers and backdoors in memory. It documents persistence mechanisms (startup LNK files, randomized AppData folders, custom file-extension registry handlers), indicators (sample SHA256 hashes and solarmarker.dat), evasion techniques (large file sizes, obfuscation), and recommended detection measures (EDR monitoring, PowerShell script logging, YARA memory scanning).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.