Skip to content

MITRE ATT&CK

Deimos in ATT&CK

1 distinct techniques

Reporting

Research mentioning Deimos

Jan 1
Sophos Threat Research

SolarMarker campaign used novel registry changes to establish persistence | SOPHOS

SolarMarker operators lured victims through SEO poisoning, fake Google Groups posts, malicious PDF-themed pages, and compromised WordPress sites that redirected users to malicious MSI installers disguised as document downloads. The installers launched legitimate decoy applications such as Wondershare PDFelement or Adobe Acrobat Pro DC while also executing PowerShell to deploy the malware, allowing the infection chain to appear benign to users. Sophos reported that SolarMarker established persistence with an unusual combination of startup .lnk files and custom Windows registry file-handler changes. The .lnk files pointed to junk files with random extensions, while the registry configuration caused those files to decrypt and reflectively load the hidden payload. Researchers also identified multiple variants with different version IDs, command-and-control servers, and encryption methods; older samples focused on stealing browser data and cryptocurrency wallets, while newer ones were primarily used to download and run additional payloads.

Jan 31
Morphisec

The Introduction of the Jupyter InfoStealer/Backdoor

Nov 6
Vmware Security

Jupyter Rising: An Update on Jupyter Infostealer - VMware Security Blog - VMware

Jun 8
Elastic Security Labs

Going Coast to Coast - Climbing the Pyramid with the Deimos Implant - Elastic Security Labs

Apr 27
Esentire

eSentire Threat Intelligence Malware Analysis: SolarMarker | eSentire

Apr 9
Palo Alto Networks Unit 42

New SolarMarker (Jupyter) Campaign Demonstrates the Malware’s Changing Attack Patterns

Jul 29
Talosintelligence Other

Threat Spotlight: Solarmarker

Apr 13
Esentire Other

Hackers Flood the Web with 100,000 Malicious Pages, Promising Professionals Free Business Forms, But Delivering… | eSentire

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.