SolarMarker Malware Uses PDF’s and SEO Keywords To Spread

June 15, 2021

Attackers behind the malware, known as SolarMarker, use PDF documents that contain search engine optimization (SEO) keywords to increase their visibility in search engines, leading potential victims to malware on a website that mimics Google Drive.

SolarMarker is a backdoor malware that steals data and credentials from infected browsers.

The hacker’s host pages on Google pages that serve as a lure for malicious downloads.

The malicious software is primarily aimed at North American users.

Once opened, the PDFs ask users to download a doc or pdf file, which then redirects users to 7 pages of TLDs such as. site,. tk and. ga.

After several redirects, users arrive at a page that is very similar to Google Drive but actually controlled by the attackers.

The page then exfiltrates stolen data to a command-and-control server and continues by creating shortcuts in the startup folder and modifying shortcuts on the desktop.

The SEO poisoning technique seems to be very effective since Microsoft 365 Defender has blocked thousands of pdf documents in different environments.

For more information, read the original story in ZDNet.

Top Stories

Related Articles

February 13, 2026 Cybersecurity researchers have uncovered a malicious Google Chrome extension designed to steal sensitive data from Meta Business more...

February 5, 2026 A security researcher at Koi named Oren Yomtov has uncovered a widespread malware operation embedded inside an more...

February 4, 2026 More than three million Fortinet devices have been exposed to a critical authentication-bypass vulnerability that is being more...

February 4, 2026 A now-patched security flaw in Docker’s built-in AI assistant exposed users to the risk of remote code more...

Picture of TND News Desk

TND News Desk

Staff writer for Tech Newsday.
Picture of TND News Desk

TND News Desk

Staff writer for Tech Newsday.

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn