SolarMarker Impersonates Indeed to Spread Malware
ID: 89e5c1fd-5894-542f-a09b-f7305035317c
STIX ID: report--89e5c1fd-5894-542f-a09b-f7305035317c
Feed Name: securityonline.info
eSentire’s Threat Response Unit uncovered a SolarMarker campaign that lures users via a fake Indeed page to download an AES-encrypted payload which deploys StellarInjector and SolarPhantom; the latter provides info-stealing and hidden VNC capabilities, stores stolen browser data in TEMP folders with XOR-based filenames, and uses legitimate digital certificates to evade detection. The report outlines the infection chain, technical artifacts, and points to IOCs and a full technical write-up on eSentire’s site.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
