Blog | G5 Cyber Security

A Technical Analysis of SolarMarker Backdoor

SolarMarker* backdoor features a multistage, heavily obfuscated PowerShell loader, which leads to a compiled backdoor being executed. This blog details how CrowdStrike Falcon Complete team detected the binary using the Falcon UI, our deobfuscation of the initial stages, and how we collaborate with the CrowdStrike Intel team to conduct further analysis and protect our customers from emerging threats. The investigation did not establish any clear link between targeted customers and malware. The malware is delivered as a fake document download targeting users performing web searches for document files.”]

Source: https://www.crowdstrike.com/blog/solarmarker-backdoor-technical-analysis/

Exit mobile version