SolarMarker Malware Evolves to Resist Takedown Attempts with Multi-Tiered Infrastructure
ID: a78245a0-ea89-5e08-85c1-d8a548985f6e
STIX ID: report--a78245a0-ea89-5e08-85c1-d8a548985f6e
Feed Name: The Hacker News
Recorded Future details SolarMarker, an evolving information-stealer active since 2020 that targets browsers, cryptocurrency wallets, VPN/RDP configurations and multiple sectors (education, government, healthcare, hospitality, SMEs). Operators use SEO-poisoned fake download sites, EXE/MSI droppers and in-memory loaders, and have developed a layered multi-tier C2 architecture (Tiers 1–4 plus auxiliary servers) and secondary testing clusters; recent variants include Delphi hVNC and PyInstaller builds, and the group employs valid Authenticode certificates and techniques to evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
