logo

Stopping a K-12 cyberattack (SolarMarker) with ThreatDown MDR

ID: 328dc42f-ca79-5932-8891-5eb5c2f17e39

STIX ID: report--328dc42f-ca79-5932-8891-5eb5c2f17e39

Feed Name: Malwarebytes Blog

Threat Score
72/100

Date Published: 2024-03-28

Date Updated: 2026-04-28

...
...

ThreatDown MDR discovered a long-dwelling SolarMarker backdoor in a large K-12 school district (present since at least 2021) that used obfuscated PowerShell and encoded payloads in AppData to execute and likely exfiltrate data to a suspicious IP (188.241.83.61); EDR was disabled so analysts used manual ARS/WMIC/netstat workflows to identify, terminate, and remove the payloads and confirm remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.