MITRE ATT&CK
Deimos in ATT&CK
1 distinct techniquesReporting
Research mentioning Deimos
SolarMarker campaign used novel registry changes to establish persistence | SOPHOS
SolarMarker operators lured victims through SEO poisoning, fake Google Groups posts, malicious PDF-themed pages, and compromised WordPress sites that redirected users to malicious MSI installers disguised as document downloads. The installers launched legitimate decoy applications such as Wondershare PDFelement or Adobe Acrobat Pro DC while also executing PowerShell to deploy the malware, allowing the infection chain to appear benign to users. Sophos reported that SolarMarker established persistence with an unusual combination of startup .lnk files and custom Windows registry file-handler changes. The .lnk files pointed to junk files with random extensions, while the registry configuration caused those files to decrypt and reflectively load the hidden payload. Researchers also identified multiple variants with different version IDs, command-and-control servers, and encryption methods; older samples focused on stealing browser data and cryptocurrency wallets, while newer ones were primarily used to download and run additional payloads.