logo

SolarMarker Impersonates Indeed to Spread Malware

ID: 89e5c1fd-5894-542f-a09b-f7305035317c

STIX ID: report--89e5c1fd-5894-542f-a09b-f7305035317c

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2024-06-17

Date Updated: 2026-04-22

Author: do son

...
...

eSentire’s Threat Response Unit uncovered a SolarMarker campaign that lures users via a fake Indeed page to download an AES-encrypted payload which deploys StellarInjector and SolarPhantom; the latter provides info-stealing and hidden VNC capabilities, stores stolen browser data in TEMP folders with XOR-based filenames, and uses legitimate digital certificates to evade detection. The report outlines the infection chain, technical artifacts, and points to IOCs and a full technical write-up on eSentire’s site.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.