Last seven days
- First activity
- Sep 15, 2026
- Last activity
- Sep 15, 2026
- Feed role
- C2
- Host form
- 1 IP / 0 hostnames
SolarMarker, also known as Jupyter, Polazert, and Yellow Cockatoo, is a modular Windows malware family first observed in 2020.
Profile source: Mallory opens in a new tabSolarMarker
SolarMarker, also known as Jupyter, Polazert, and Yellow Cockatoo, is a modular Windows malware family first observed in 2020. It combines a .NET backdoor with information-stealing, keylogging, form-grabbing, cryptocurrency-wallet theft, remote-control, and proxy capabilities. SolarMarker commonly uses search-engine optimization poisoning, deceptive document- or software-themed landing pages, and signed oversized installers disguised as document downloads to induce user execution. Installers often run legitimate decoy software while deploying the malware.
SolarMarker establishes user-level persistence through a Startup-folder shortcut and a malicious custom file-association handler that invokes PowerShell to decrypt and reflectively load an in-memory .NET payload. It employs obfuscation, encoded and encrypted payloads, random names and decoy files, code-signing certificates, and oversized executable content to hinder detection and automated analysis. Its backdoor communicates over encrypted HTTP, fingerprints infected hosts, accepts PowerShell commands, transfers or loads additional payloads, and supports remote access. Observed variants can steal browser credentials, cookies, autofill data, saved payment-card data, VPN and remote-desktop configurations, and cryptocurrency-wallet data. Operators have also used remote-control functionality to access active browser sessions directly on victim devices for account takeover and financial fraud. Campaigns have broadly targeted users and organizations, including business and financial-sector personnel, rather than a narrowly defined industry vertical. SolarMarker infrastructure was reported to have become inactive in 2024.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
ERYTHRITE has technical overlaps to another group multiple IT security organizations have labeled as Solarmarker.
MITRE ATT&CK
Reporting
A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.
SolarMarker operators lured victims through SEO poisoning, fake Google Groups posts, malicious PDF-themed pages, and compromised WordPress sites that redirected users to malicious MSI installers disguised as document downloads. The installers launched legitimate decoy applications such as Wondershare PDFelement or Adobe Acrobat Pro DC while also executing PowerShell to deploy the malware, allowing the infection chain to appear benign to users. Sophos reported that SolarMarker established persistence with an unusual combination of startup .lnk files and custom Windows registry file-handler changes. The .lnk files pointed to junk files with random extensions, while the registry configuration caused those files to decrypt and reflectively load the hidden payload. Researchers also identified multiple variants with different version IDs, command-and-control servers, and encryption methods; older samples focused on stealing browser data and cryptocurrency wallets, while newer ones were primarily used to download and run additional payloads.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.