{"id":4152,"date":"2022-05-05T10:43:34","date_gmt":"2022-05-05T15:43:34","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=4152"},"modified":"2022-05-05T10:43:35","modified_gmt":"2022-05-05T15:43:35","slug":"dont-let-solarmarker-fool-your-information","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/dont-let-solarmarker-fool-your-information\/","title":{"rendered":"Don&#8217;t let SolarMarker fool your information"},"content":{"rendered":"\n<p>Some may remember Solarmarker which is a malware campaign that has been active since September 2020, and telemetry data points to malicious actions since April 2020. Which is a backdoor featuring a malware family known for its backdoor and data stealing capabilities, delivered primarily through search engine optimization (SEO) manipulation to convince users to download malicious documents and now a new version of this threat has been identified.<\/p>\n\n\n\n<p>It is worth noting that SolarMarker has the ability to leak auto-fill data, saved passwords, and saved credit card information from victims&#8217; web browsers. In addition to the typical information theft capabilities, SolarMarker has extras, such as file transfer and execution of commands received from a C2 server, as well as defense evasion-oriented techniques.<\/p>\n\n\n\n<p>It should be noted that SolarMarker has several infection methods, the first method being achieved by creating Google Group discussions. In which attackers create multiple fake Google groups, each containing 500-600 fake conversation entries, targeting the most common search terms on a wide variety of topics with links that for obvious reasons you should not access.<\/p>\n\n\n\n<p>In the following method, use the SEO in which you store in PDF files hosted on websites; search engines in which they directly linked to the PDF files and when the search engine link is clicked, the web browser opens the malicious PDFs as it would any other PDF document on the web.<\/p>\n\n\n\n<p>And last but not least are WordPress sites compromised to deliver the content, but instead use HTML pages hosted on the compromised site. The HTML source of these malicious pages contains collections of links for other search terms, all connected to other malicious pages on the same compromised server.<\/p>\n\n\n\n<p>Some time ago SolarMarker was more prevalent in Western countries, especially in the US, but you never know where these threats arrive, so taking some security measures would not be bad.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Some may remember Solarmarker which is a malware campaign that has been active since September 2020 and unfortunately it seems to be back&#8230;<\/p>\n","protected":false},"author":1,"featured_media":4153,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-4152","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Don&#039;t let SolarMarker fool your information - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Some may remember Solarmarker which is a malware campaign that has been active since September 2020 and unfortunately it seems to be back...\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/dont-let-solarmarker-fool-your-information\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Don&#039;t let SolarMarker fool your information - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Some may remember Solarmarker which is a malware campaign that has been active since September 2020 and unfortunately it seems to be back...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/dont-let-solarmarker-fool-your-information\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2022-05-05T15:43:34+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-05-05T15:43:35+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/04\/solar.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"450\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-let-solarmarker-fool-your-information\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-let-solarmarker-fool-your-information\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"Don&#8217;t let SolarMarker fool your information\",\"datePublished\":\"2022-05-05T15:43:34+00:00\",\"dateModified\":\"2022-05-05T15:43:35+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-let-solarmarker-fool-your-information\\\/\"},\"wordCount\":316,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-let-solarmarker-fool-your-information\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/04\\\/solar.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-let-solarmarker-fool-your-information\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-let-solarmarker-fool-your-information\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-let-solarmarker-fool-your-information\\\/\",\"name\":\"Don't let SolarMarker fool your information - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-let-solarmarker-fool-your-information\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-let-solarmarker-fool-your-information\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/04\\\/solar.jpg\",\"datePublished\":\"2022-05-05T15:43:34+00:00\",\"dateModified\":\"2022-05-05T15:43:35+00:00\",\"description\":\"Some may remember Solarmarker which is a malware campaign that has been active since September 2020 and unfortunately it seems to be back...\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-let-solarmarker-fool-your-information\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-let-solarmarker-fool-your-information\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-let-solarmarker-fool-your-information\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/04\\\/solar.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/04\\\/solar.jpg\",\"width\":1000,\"height\":450},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/dont-let-solarmarker-fool-your-information\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Don&#8217;t let SolarMarker fool your information\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Don't let SolarMarker fool your information - Truxgo Server Blog","description":"Some may remember Solarmarker which is a malware campaign that has been active since September 2020 and unfortunately it seems to be back...","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/dont-let-solarmarker-fool-your-information\/","og_locale":"es_MX","og_type":"article","og_title":"Don't let SolarMarker fool your information - Truxgo Server Blog","og_description":"Some may remember Solarmarker which is a malware campaign that has been active since September 2020 and unfortunately it seems to be back...","og_url":"https:\/\/truxgoservers.com\/blog\/dont-let-solarmarker-fool-your-information\/","og_site_name":"Truxgo Server Blog","article_published_time":"2022-05-05T15:43:34+00:00","article_modified_time":"2022-05-05T15:43:35+00:00","og_image":[{"width":1000,"height":450,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/04\/solar.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/dont-let-solarmarker-fool-your-information\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/dont-let-solarmarker-fool-your-information\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"Don&#8217;t let SolarMarker fool your information","datePublished":"2022-05-05T15:43:34+00:00","dateModified":"2022-05-05T15:43:35+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/dont-let-solarmarker-fool-your-information\/"},"wordCount":316,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/dont-let-solarmarker-fool-your-information\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/04\/solar.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/dont-let-solarmarker-fool-your-information\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/dont-let-solarmarker-fool-your-information\/","url":"https:\/\/truxgoservers.com\/blog\/dont-let-solarmarker-fool-your-information\/","name":"Don't let SolarMarker fool your information - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/dont-let-solarmarker-fool-your-information\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/dont-let-solarmarker-fool-your-information\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/04\/solar.jpg","datePublished":"2022-05-05T15:43:34+00:00","dateModified":"2022-05-05T15:43:35+00:00","description":"Some may remember Solarmarker which is a malware campaign that has been active since September 2020 and unfortunately it seems to be back...","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/dont-let-solarmarker-fool-your-information\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/dont-let-solarmarker-fool-your-information\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/dont-let-solarmarker-fool-your-information\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/04\/solar.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/04\/solar.jpg","width":1000,"height":450},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/dont-let-solarmarker-fool-your-information\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Don&#8217;t let SolarMarker fool your information"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4152","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=4152"}],"version-history":[{"count":1,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4152\/revisions"}],"predecessor-version":[{"id":4154,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4152\/revisions\/4154"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/4153"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=4152"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=4152"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=4152"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}