Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

SolarisLoader

68
Global rank
29 infographic chevron month
Month rank
31 infographic chevron week
Week rank
0
IOCs

SolarisLoader is a malware loader designed to neutralize security infrastructure before deploying high-risk secondary payloads. It utilizes a "Bring Your Own Vulnerable Driver" technique to gain kernel-level access and terminate antivirus processes. To remain undetected, the malware patches internal Windows monitoring interfaces and isolates the machine from security updates. Finally, it establishes a resilient three-layer persistence mechanism involving scheduled tasks, registry backups, and a watchdog component.

Loader
Type
Unknown
Origin
1 June, 2026
First seen
16 August, 2026
Last seen

How to analyze SolarisLoader with ANY.RUN

Type
Unknown
Origin
1 June, 2026
First seen
16 August, 2026
Last seen

IOCs

IP addresses
196.251.107.186
23.48.23.166
20.190.159.68
23.59.18.102
48.192.1.65
40.126.31.71
23.11.41.157
48.209.133.15
142.251.155.119
74.178.76.54
172.211.123.250
2.23.246.9
48.209.138.189
135.232.92.137
62.60.226.232
40.126.31.67
142.251.13.94
196.251.107.163
172.211.123.249
163.181.254.181
Hashes
ba25fefad8a545281ae6f99515926717ebe8c1146805795bedd32041192a0688
d2bb091268ade68ad8121d2184d0fbce128070156304bd4de312e6fbd267409c
df3934740546e59befa158654a31f97380629af8a19966e8af135a1840925fd6
88486926b72fcddd4a3d4e21dbc246f0de12d76b016bcae204c6d76d0a07b143
985ead812b8b99573d2567169d73968a3754b4fbea16447bea2ac878974e6110
3b85e759603b0c10c54cfcec972450072daa2aee0a52dbb0fa5f40af012d72e3
598cac1f258659e24c5518646ef5d60407220e804cfc8eff13acf2cb3150c729
64986d846abbeeb612f8b6c606a2b18863678209a1b756f45b3b6dc23c237377
6db32a2ea6d0685b33bfcd8a5807c8a18d14f77d974fb70ce9186adaf151ddde
f59d49d859384c7104db15592f0985146691e006f55bac77904b19cd7780e0db
da644749ec4e5a112e92512de0306561af59860f5135674ee65349579b2f4b81
00338677cdf3ee87ed766f01f5be4ecfa1ec88028978b44f6dd4b0881aff6072
9e60fe20c86ae236b4b8f2b98a7df8f7aa8b7545cf289bb003ddbe2e8be49454
63b14543360f5e89942ea8d5113526e64fbc71c1207328f0136b3a495d921dd0
83b3fb548b094aa66bbf9da57c4d5a49acaa76914121e90aa05fb53ab47367e0
d62618e33bfb74f02074ac9832c34b63bcd3bfef92a8d8039bd5c11c4269461c
3fa98d58f41c76a6486fd7aed8cfc50c1cff1369f5eaa6ad412094c2986e952e
0d581dac21e6140f342a435a92a52e372cea57bfb75cf41cc135b8ff39b875fd
cebe9e8611d80b8c90ad50500eee6c27eaadc1aa74fd83c912e3ab6a4e1f07f2
838df86a8c6a49d047694246949d1a4aeab5b85c5d50ddeb55bec817f3931cfa
Domains
settings-win.data.microsoft.com
login.live.com
activation-v2.sls.microsoft.com
ocsp.digicert.com
slscr.update.microsoft.com
fe3cr.delivery.mp.microsoft.com
crl.microsoft.com
www.microsoft.com
c.pki.goog
client.wns.windows.com
go.microsoft.com
google.com
www.google.com
ocsp.digicert.cn
www.bing.com
th.bing.com
oneocsp.microsoft.com
t.me
edge.microsoft.com
config.edge.skype.com
URLs
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
http://196.251.107.186/zs/config.bin
https://login.live.com/rst2.srf
https://settings-win.data.microsoft.com/settings/v3.0/onesettings/client?osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&localdeviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&attrdataver=186&osuilocale=en-us&osskuid=48&app=wosc&appver=&isflightingenabled=0&telemetrylevel=1&devicefamily=windows.desktop
https://login.live.com/ppsecure/deviceaddcredential.srf
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://settings-win.data.microsoft.com/settings/v3.0/flightsettings/fsservice?processorclockspeed=3094&isretailos=1&oemmanufacturername=dell&flightingpolicyvalue=3&enablepreviewbuilds=4294967295&osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&managepreviewbuilds=3&branchreadinesslevelsource=0&attrdataver=186&processorcores=6&branchreadinesslevelraw=16&totalphysicalram=6144&tpmversion=0&oemmodelnumber=dell&systemvolumetotalcapacity=260281&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&app=fss&appver=10.0&smartactivehoursstate=1&activehoursstart=20&securebootcapable=0&activehoursend=13&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://settings-win.data.microsoft.com/settings/v3.0/waas/featuremanagement?isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&currentbranch=vb_release&accountfirstchar=&activationchannel=retail&oemmodel=dell&flightring=retail&attrdataver=186&installlanguage=en-us&osuilocale=en-us&webexperience=1&flightingbranchname=&chassistypeid=1&osskuid=48&app=cdm&installdate=1661339444&appver=&osarchitecture=amd64&defaultuserregion=244&telemetrylevel=1&osversion=10.0.19045.4046&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
https://settings-win.data.microsoft.com/settings/v3.0/wsd/updatehealthtools?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&sampleid=s:95271487&appver=10.0.19041.3626&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=sedimentpack&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://slscr.update.microsoft.com/sls/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://www.google.com/webhp?gws_rd=ssl
http://www.google.com/webhp
Last Seen at
Last Seen at

Recent blog posts

post image
Intelligence-Driven SOC: Modernizing Threat M...
watchers 10196
comments 0
post image
Supply Chain Security: How ANY.RUN Helps US a...
watchers 5483
comments 0
post image
Smile, You're on Camera. Part 2: Hiring Lazar...
watchers 42946
comments 0

Key Takeaways

  • Kernel-Level Defense Dismantling: SolarisLoader utilizes a "Bring Your Own Vulnerable Driver" (BYOVD) technique, exploiting a vulnerable Safetica endpoint protection driver (CVE-2026-0828) to gain kernel-level access and forcibly terminate security processes.
  • Telemetry Blinding: The malware prevents the operating system from logging or reporting malicious activity by patching the Antimalware Scan Interface (AMSI) and Event Tracing for Windows (ETW) in memory via direct opcode modification.
  • Resilient Triple-Layer Persistence: The infection survives standard cleanup through a combination of scheduled tasks, registry-backed backups (ICtrlData), and a watchdog process that injects code into legitimate system files like RuntimeBroker.exe.
  • ANY.RUN’s Interactive Sandbox analysis confirms that the loader utilizes a silent COM-elevation/UAC-bypass path via dllhost.exe, enabling it to gain administrative privileges without triggering user-facing notifications or consent prompts.

ANY.RUN detects SolarisLoader fast, providing a response-ready report for SOC teams ANY.RUN detects SolarisLoader fast, providing a response-ready report for SOC teams

  • Active Malware-as-a-Service (MaaS) Cycle: The loader is in active development, functioning as a primary delivery vehicle for secondary payloads such as StealC, Amadey, and REMCOS RAT.

SolarisLoader: A Stealthy Multi-Stage Defense-Dismantling Malware

What is SolarisLoader?

SolarisLoader is a sophisticated Malware-as-a-Service (MaaS) delivery vehicle designed to dismantle a system's security infrastructure before deploying high-risk secondary payloads. First identified in early 2026, the malware is characterized by its aggressive approach to antivirus software: rather than merely attempting to hide, it actively seeks and destroys security processes from the kernel level. While it does not typically steal data itself, it creates a "blind spot" on the infected host, clearing the way for infamous stealers and loaders like Amadey.

The malware is primarily distributed through fake software installers bundled with cracked or pirated versions of popular applications and games. This distribution strategy exploits users who are already attempting to bypass legitimate software protocols, making them less likely to question the silent background installations or administrative requests that occur during the infection chain. In some instances, the loader will even drop and execute the legitimate cracked software after the infection is complete to further reduce user suspicion.

Technical analysis reveals that SolarisLoader is a highly professional product undergoing rapid evolution. Since its emergence, researchers have tracked its maturation from version 1.2.0 to 1.8.2, observing iterative refinements in its C2 communication protocols, anti-analysis techniques, and persistence mechanisms. Its core design prioritizes persistence and stealth; it utilizes a dedicated watchdog component (often recovered via PDB paths as "Solaris") that monitors the system and automatically re-initiates the malware implant if it is terminated or deleted. By combining kernel-level exploits with telemetry patching, SolarisLoader ensures that a compromised system's own security stack reports nothing unusual even as secondary payloads are actively executed.

How SolarisLoader Threatens Businesses and Organizations

For modern enterprises, SolarisLoader’s primary threat lies in its ability to create a "permanent blind spot" on an infected workstation, ensuring that subsequent malicious activities go entirely undetected by traditional monitoring tools.

Unlike most loaders that attempt to hide from security software, SolarisLoader uses a "Bring Your Own Vulnerable Driver" (BYOVD) technique to gain kernel-level access. By exploiting CVE-2026-0828 in the Safetica endpoint protection driver, the malware achieves the same system privileges as the security software itself, allowing it to forcibly terminate Windows Defender and major third-party antivirus processes like Avast, AVG, and 360 Total Security. The malware systematically "blinds" the operating system by patching the Antimalware Scan Interface (AMSI) and Event Tracing for Windows (ETW) directly in memory. This ensures that even if follow-on payloads execute suspicious scripts or file operations, the OS will not generate the event logs or telemetry needed for EDR (Endpoint Detection and Response) or SOC teams to flag the intrusion.

Victimology: Who Is Most Vulnerable?

The targeting profile of SolarisLoader is opportunistic and designed to exploit gaps in both technical controls and user behavior. While its distribution is global, specific technical markers reveal focused targeting strategies:

TI Lookup shows all the latest threat intel on Solaris Loader TI Lookup shows all the latest threat intel on Solaris Loader

  • US and EU Companies: According to ANY.RUN’s [Threat Intelligence Lookup], the majority of Solaris Loader attacks affected businesses from the United States and the European Union.
  • Organizations with Permissive Local Admin Rights: SolarisLoader relies on gaining administrative privileges to execute its most damaging stages, such as driver loading and hosts file modification. It utilizes a silent COM-elevation/UAC-bypass path via dllhost.exe, which means users running with local administrative rights can be compromised without ever seeing a permission prompt.
  • Global Enterprise Users: The malware's targeting of global suites like Avast, AVG, and ReasonLabs makes it a universal threat. Any organization relying solely on signature-based antivirus or standard Windows telemetry (AMSI/ETW) is highly vulnerable, as SolarisLoader's telemetry-blinding and BYOVD techniques are specifically designed to defeat these common defenses.
  • Secondary Infection Targets: Systems already compromised by other loaders, such as XTinyLoader or Amadey, are frequently targeted for SolarisLoader deployment, as it is often used as an intermediate stage to clear security hurdles before a final payload is delivered.

    How Does SolarisLoader Function?

    Detonating a SolarisLoader sample inside ANY.RUN’s Interactive Sandbox reveals a highly aggressive and multi-staged attack chain designed to neutralize system defenses before establishing a permanent foothold. By moving beyond simple file execution, the loader utilizes a series of strategic maneuvers to blind the operating system and deliver high-risk secondary payloads.
Stage 1: Initial Execution and Silent Elevation

The infection typically begins when the user executes a malicious installer, which runs from the user's Temp directory. Upon launch, the malware drops several staged components into the %TEMP% folder, including WinSysKdrv.exe, 0_1671390.exe, and 1_1675328.exe. SolarisLoader detonated inside ANY.RUN’s Interactive Sandbox SolarisLoader detonated inside ANY.RUN’s Interactive Sandbox

To gain the administrative privileges necessary for its subsequent stages without alerting the user, the loader spawns WinSysKdrv.exe through dllhost.exe (COM surrogate), a technique consistent with a silent COM-elevation/UAC-bypass path. Early in this execution phase, the sample creates the SOLARIS mutex, which acts as both an execution guard and an infection marker on the host to prevent multiple instances from running simultaneously.

SolarisLoader mutex detected by ANY.RUN’s Interactive Sandbox SolarisLoader mutex detected by ANY.RUN’s Interactive Sandbox

Stage 2: Defense Dismantling and Network Isolation

Once elevated, SolarisLoader immediately begins systematically dismantling the endpoint's security stack. The sandbox analysis highlights several critical actions:

  • Neutralizing Windows Defender: The malware disables real-time protection and modifies registry values associated with security policies and exclusion lists to prevent detection.

SolarisLoader disables MS Defender SolarisLoader disables MS Defender

  • Kernel-Level Tampering: The loader creates or modifies Windows services specifically tied to kernel-driver loading. This allows the malware to achieve defense evasion by operating at the same privilege level as the operating system's core.
  • Network Isolation: To prevent the machine from receiving updates or communicating with security telemetry servers, the malware rewrites the Windows hosts file. It redirects critical security and telemetry domains to unreachable local addresses, effectively isolating the host from external remediation.
Stage 3: Resilient Persistence and Watchdog Behavior

SolarisLoader injects itself into a legitimate process SolarisLoader injects itself into a legitimate process

SolarisLoader is engineered for maximum resilience against manual or automated cleanup. It ensures survival through two primary mechanisms:

  • Process Injection: The malware injects malicious code into legitimate system processes, specifically RuntimeBroker.exe and sihost.exe. This acts as a watchdog, where these trusted system components monitor the infection and can re-initiate the malware if it is interrupted.
  • Registry-Based Fallback: For long-term survival, it sets a login/logoff helper path in the registry as a fallback mechanism, ensuring the loader re-executes whenever a user logs into the system.

Logon-script persistence fallback via the registry Logon-script persistence fallback via the registry

Stage 4: Host Reconnaissance (Fingerprinting)

Before contacting its command-and-control (C2) infrastructure, SolarisLoader performs a thorough reconnaissance of the infected workstation to create a unique host fingerprint.

Host fingerprinting: computer name, machine GUID, languages, install date, location Host fingerprinting: computer name, machine GUID, languages, install date, location

The sandbox observed the malware harvesting the following data points: Computer name and machine GUID, Windows installation date and system location settings, Supported system languages.

Stage 5: C2 Communication and Payload Delivery

The final stage of the attack involves establishing communication with the attacker's infrastructure to fulfill its role as a loader. The sample beacons to a specific C2 endpoint at 196[.]251[.]107[.]186/api.php.

SolarisLoader’s C2 beacon SolarisLoader’s C2 beacon

Following this check-in, the loader was observed pulling additional malicious payloads, including bot_x64.exe and klr.exe, from a secondary IP address (192[.]162[.]199[.]186) that has been flagged as malicious. This confirms that SolarisLoader's ultimate goal is to serve as a delivery vehicle for further staged malicious activity.

How Businesses Can Use ANY.RUN’s Threat Intelligence Against Solaris

Because SolarisLoader operates as an evolving Malware-as-a-Service (MaaS) with infrastructure and file names that rotate rapidly, traditional static blocklists are often insufficient for long-term protection. Security teams must shift from tracking temporary indicators to identifying the durable technical fingerprints and behavioral patterns of the operation. By leveraging ANY.RUN’s Threat Intelligence, organizations can stay ahead of these evolving campaigns.

Threat Intelligence Lookup allows analysts to pivot from a single suspicious artifact to an entire cluster of related malicious activity.

threatName:"solaris"

Threat Intelligence Lookup provides actionable SolarisLoader indicators and TTPs Threat Intelligence Lookup provides actionable SolarisLoader indicators and TTPs

TI Lookup delivers a complete context on the threat, providing rich intelligence on SolarisLoader attacks, including network indicators, mutexes, file names, as well as full sandbox sessions that demonstrate the entire execution cycle from start to finish. For organizations requiring automated, high-speed protection, ANY.RUN’s Threat Intelligence Feeds provide a real-time stream of validated indicators. These feeds deliver a continuous flow of the latest C2 domains and malicious IPs directly into SIEM, SOAR, and EDR platforms. By integrating these feeds, teams can automatically block emerging malicious infrastructure, such as rotating fake-installer portals, and detect active breaches before data exfiltration occurs.

Conclusion

SolarisLoader represents a strategic shift in the cybercrime landscape, moving beyond simple evasion to the systematic neutralization of the entire security stack. By combining kernel-level exploits with telemetry blinding, the malware creates an environment where secondary payloads can operate with total visibility while the operating system remains unaware of the intrusion. To combat this evolving threat, organizations must move beyond static blocklists and reactive defenses, adopting a strategy that prioritizes behavioral analysis and proactive threat intelligence. Utilizing interactive sandboxing is essential to deobfuscate the loader's multi-stage logic and identify the durable technical signals, such as unauthorized driver loading and system-level telemetry tampering, before the successful delivery of high-risk secondary infections.

Frequently Asked Questions: SolarisLoader

1. What is SolarisLoader?

SolarisLoader is a specialized malware delivery vehicle designed to gain a persistent foothold on a host, disable its security tools, and deliver secondary infections like stealers and remote access trojans. It is sold on a subscription basis, allowing various threat actors to deploy it as a primary entry point for broader campaigns.

2. How does SolarisLoader bypass traditional security software?

The malware utilizes a "Bring Your Own Vulnerable Driver" (BYOVD) technique, exploiting a documented vulnerability in a legitimate third-party driver to achieve kernel-level privileges. This gives the loader the same system permissions as the security software it is attacking, allowing it to forcibly terminate security processes and endpoint detection services.

3. Why is a "clean" security scan result not trustworthy if this malware is present?

SolarisLoader specifically patches internal monitoring interfaces, such as the Antimalware Scan Interface (AMSI) and Event Tracing for Windows (ETW), in memory. This "blinds" the system’s own telemetry, preventing it from logging or reporting malicious activity even if the security software remains active.

4. How can organizations use interactive sandboxing and threat intelligence to stay protected?

Interactive sandboxing is essential to expose the modular logic that evades automated scanners, allowing defenders to see how the malware escalates privileges and dismantles defenses in real-time. Proactive threat intelligence allows teams to identify stable build-chain fingerprints and block rotating C2 infrastructure before it reaches the endpoint.

5. What are the key indicators of a SolarisLoader infection?

Defenders should monitor for unauthorized redirects in the system hosts file (pointing security domains to unroutable addresses), the creation of scheduled tasks disguised as system security checks, and unauthorized additions to security exclusion lists. The presence of specific binary data in the system registry also serves as a backup for the malware's self-healing loop.

HAVE A LOOK AT

Phishing kit screenshot
Phishing kit
tycoon evilproxy sneaky2fa
Phishing kits are pre-packaged sets of malicious tools designed to make it easy for cybercriminals to launch phishing attacks. These kits replicate legitimate websites, steal credentials, and often include backend infrastructure for managing stolen data.
Read More
Zloader screenshot
Zloader
zloader trojan loader
Zloader is a banking trojan that uses webinjects and VNC clients to still banking credentials. This Trojan is based on leaked code from 2011, but despite its age, Zloader’s popularity has been only increasing through early 2020, when it relied on COVID-19 themed attacks.
Read More
DarkTortilla screenshot
DarkTortilla
darktortilla
DarkTortilla is a crypter used by attackers to spread harmful software. It can modify system files to stay hidden and active. DarkTortilla is a multi-stage crypter that relies on several components to operate. It is often distributed through phishing sites that look like real services.
Read More
BQTLock screenshot
BQTLock
bqtlock baqiyatlock
BQTLock is a ransomware-as-a-service (RaaS) malware family that emerged in 2025 and quickly gained attention due to its combination of file encryption, credential theft, and data exfiltration. BQTLock encrypts files using a hybrid AES-256 and RSA-4096 encryption scheme, demands payment in Monero cryptocurrency, and performs data theft and system reconnaissance.
Read More
WhiteSnake screenshot
WhiteSnake
whitesnake
WhiteSnake is a stealer with advanced remote access capabilities. The attackers using this malicious software can control infected computers and carry out different malicious activities, including stealing sensitive files and data, recording audio, and logging keystrokes. WhiteSnake is sold on underground forums and often spreads through phishing emails.
Read More
X-Files screenshot
X-Files
xfiles
X-FILES Stealer is a sophisticated malware designed to infiltrate systems and steal sensitive information, targeting login credentials for email, social media, and other personal accounts. It captures data and transmits it back to the attacker’s command-and-control server. X-FILES Stealer employs advanced evasion techniques to avoid detection, making it a persistent threat in the cyber landscape.
Read More