johnk3r Profile Banner
Padawan Profile
Padawan

@johnk3r

Followers
1K
Following
3K
Statuses
595

Threat Hunter

Buenos Aires
Joined February 2015
Don't wanna be here? Send us removal request.
@johnk3r
Padawan
4 days
Tweet media one
Tweet media two
0
0
3
@johnk3r
Padawan
13 days
This is the first time I've seen this Windows feature abused in malware (I need to study it further). Perhaps it will become a trend, given the scale of attacks seen in recent days. Final payload: @dodo_sec @1ZRR4H @Merlax_
1
1
6
@johnk3r
Padawan
13 days
@ValidinLLC Ref.: IoC:
0
0
2
@johnk3r
Padawan
15 days
RT @dodo_sec: I've uploaded the final stage of yet another BR Delphi banking RAT to malware bazaar. Still haven't seen something that ties…
0
11
0
@johnk3r
Padawan
16 days
@SquiblydooBlog @smica83 "_main.pyc" has a lot of garbage, the image above is the most relevant part.
0
0
4
@johnk3r
Padawan
1 month
RT @AustinLarsen_: 🚨 New: Zero-day vulnerability CVE-2025-0282 in Ivanti Connect Secure VPN is being actively exploited, including by suspe…
0
39
0
@johnk3r
Padawan
2 months
@jaimeblascob The extension "llimhhconnjiflfimocjggfjdlmlhblm - Reader Mode" has traces of compromise.
Tweet media one
0
0
6
@johnk3r
Padawan
2 months
@dodo_sec @SquiblydooBlog Great insight. I found it curious how long the infection chain was for the final payload to be a UPX.
1
0
3
@johnk3r
Padawan
2 months
Tweet media one
@GetWinEvent_
tooManyOpenThreats
2 months
YES: HTA/Delphi/AutoIt still "hot" for brazilian malware developers! Great work by @CrowdStrike
Tweet media one
1
0
7
@johnk3r
Padawan
2 months
@RussianPanda9xx disappeared from my telemetry too :(
1
0
2
@johnk3r
Padawan
2 months
@Merlax_ @1ZRR4H IoC: Hunt: User-Agent: AdvancedInstaller + POST: licenseUser\.php C2: taco-keys\.com puta-key\.com search-keys\.com cococokeys\.com Ref.:
1
0
8