Skip to content

SolarMarker

SolarMarker, also known as Jupyter, Polazert, and Yellow Cockatoo, is a modular Windows malware family first observed in 2020.

Profile source: Mallory opens in a new tab

SolarMarker

Family profile

SolarMarker, also known as Jupyter, Polazert, and Yellow Cockatoo, is a modular Windows malware family first observed in 2020. It combines a .NET backdoor with information-stealing, keylogging, form-grabbing, cryptocurrency-wallet theft, remote-control, and proxy capabilities. SolarMarker commonly uses search-engine optimization poisoning, deceptive document- or software-themed landing pages, and signed oversized installers disguised as document downloads to induce user execution. Installers often run legitimate decoy software while deploying the malware.

SolarMarker establishes user-level persistence through a Startup-folder shortcut and a malicious custom file-association handler that invokes PowerShell to decrypt and reflectively load an in-memory .NET payload. It employs obfuscation, encoded and encrypted payloads, random names and decoy files, code-signing certificates, and oversized executable content to hinder detection and automated analysis. Its backdoor communicates over encrypted HTTP, fingerprints infected hosts, accepts PowerShell commands, transfers or loads additional payloads, and supports remote access. Observed variants can steal browser credentials, cookies, autofill data, saved payment-card data, VPN and remote-desktop configurations, and cryptocurrency-wallet data. Operators have also used remote-control functionality to access active browser sessions directly on victim devices for account takeover and financial fraud. Campaigns have broadly targeted users and organizations, including business and financial-sector personnel, rather than a narrowly defined industry vertical. SolarMarker infrastructure was reported to have become inactive in 2024.

Capabilities

  • Credential Theft
  • Crypto Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Process Injection
  • Reconnaissance
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 15, 2026
Last activity
Sep 15, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • TR1

Leading providers

  • TIGOVA NETWORK LIMITED1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
erythrite

ERYTHRITE has technical overlaps to another group multiple IT security organizations have labeled as Solarmarker.

MITRE ATT&CK

SolarMarker in ATT&CK

59 distinct techniques

Techniques

59 techniques
T1553.002 Code Signing T1608.006 SEO Poisoning T1204.002 Malicious File T1059 Command and Scripting Interpreter T1005 Data from Local System T1189 Drive-by Compromise T1056.001 Keylogging T1059.001 PowerShell T1027 Obfuscated Files or Information T1555 Credentials from Password Stores T1584.004 Server T1036 Masquerading T1649 Steal or Forge Authentication Certificates T1218.007 Msiexec T1566.002 Spearphishing Link T1204 User Execution T1219 Remote Access Tools T1539 Steal Web Session Cookie T1564.003 Hidden Window T1620 Reflective Code Loading T1090 Proxy T1105 Ingress Tool Transfer T1059.003 Windows Command Shell T1055 Process Injection T1056.003 Web Portal Capture T1070.004 File Deletion T1140 Deobfuscate/Decode Files or Information T1547.009 Shortcut Modification T1547 Boot or Logon Autostart Execution T1583 Acquire Infrastructure T1564 Hide Artifacts T1547.001 Registry Run Keys / Startup Folder T1585 Establish Accounts T1059.005 Visual Basic T1112 Modify Registry T1027.001 Binary Padding T1598 Phishing for Information T1078 Valid Accounts T1071 Application Layer Protocol T1082 System Information Discovery T1574 Hijack Execution Flow T1555.003 Credentials from Web Browsers T1055.012 Process Hollowing T1546.001 Change Default File Association T1041 Exfiltration Over C2 Channel T1573 Encrypted Channel T1119 Automated Collection T1560.001 Archive via Utility T1127 Trusted Developer Utilities Proxy Execution T1584.001 Domains T1059.007 JavaScript T1497 Virtualization/Sandbox Evasion T1552 Unsecured Credentials T1497.001 System Checks T1053.005 Scheduled Task T1083 File and Directory Discovery T1001 Data Obfuscation T1552.001 Credentials In Files T1574.011 Services Registry Permissions Weakness

Reporting

Research mentioning SolarMarker

Aug 15
Github Web

GitHub - tjnel/certgraveyard_yara: Automated YARA rule generation from the Cert Central compromised certificate database. · GitHub

A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.

Jul 28
Sekoia

Exposing FakeBat loader: distribution methods and adversary infrastructure

Jun 23
Github Web

DE-TH-Aura/Defender for Endpoint/ExternalData - Cert Central, CertReport.md at main · SecurityAura/DE-TH-Aura · GitHub

Jun 22
Squiblydoo

Using the Cert Graveyard - Squiblydoo.blog

Apr 1
Squiblydoo

The CertGraveyard - Squiblydoo.blog

Mar 25
Github Web

GitHub - Squiblydoo/certReport: A tool to support the reporting of Authenticode Certificates by reducing the effort on individuals to report. · GitHub

Jan 1
Sophos Threat Research

SolarMarker campaign used novel registry changes to establish persistence | SOPHOS

SolarMarker operators lured victims through SEO poisoning, fake Google Groups posts, malicious PDF-themed pages, and compromised WordPress sites that redirected users to malicious MSI installers disguised as document downloads. The installers launched legitimate decoy applications such as Wondershare PDFelement or Adobe Acrobat Pro DC while also executing PowerShell to deploy the malware, allowing the infection chain to appear benign to users. Sophos reported that SolarMarker established persistence with an unusual combination of startup .lnk files and custom Windows registry file-handler changes. The .lnk files pointed to junk files with random extensions, while the registry configuration caused those files to decrypt and reflectively load the hidden payload. Researchers also identified multiple variants with different version IDs, command-and-control servers, and encryption methods; older samples focused on stealing browser data and cryptocurrency wallets, while newer ones were primarily used to download and run additional payloads.

Jan 31
Morphisec

The Introduction of the Jupyter InfoStealer/Backdoor

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.