Sign in

Simon Kenin

@k3yp0d.bsky.social
383 followers 160 following 203 posts

Threat Hunter at SentinelOne | curatedintel.org Member | k3yp0d.blogspot.com | Opinions are of my own voices inside my own head | memes and music are welcome

PostsRepliesMedia
Simon Kenin @k3yp0d.bsky.social · 20/09/2026
4/4 Some more samples: fc9f0efba04f51b46036af4481ddc5fa -> cde27220d1a12fe5ecfcdfa8bc67bc32 e943e9e9d12c36b3587350d5e92abcd5 and 5ee09890d9b9423e5754c99e50623043 -> c760ac33a45aaa90d758335fcbc5117c 3334b6e453f75705f56d204b99229164 -> 76adfec4b0ee52ba39f3c52b47677c13
010
Simon Kenin @k3yp0d.bsky.social · 20/09/2026
3/4 Example payload from MSI: dac640a37d5096c47fdd8f745b9a9115 89a69c637a733e6e7ac37e8e52d6eefd0a632eee 2a373c2ace484d2ada44a26b356de18b5ec8e9d57c5060d42ff239ec1705059c Most MSI files contains different unique payloads.
100
Simon Kenin @k3yp0d.bsky.social · 20/09/2026
2/4 The ClickFix payloads are MSI installers hosted at several domains such as vostokinc[.]info and uasputnik[.]com: 670086be6d64b3fc9d9edcbaf8986c02 540a088249b4ab8c4b934f436bd244d706674423 3b039a36ed576353cb7eb1054b6ac56f42f63a6fc447edeb58c48b4bb7537482
100
Simon Kenin @k3yp0d.bsky.social · 20/09/2026
1/4 An ongoing campaign compromised multiple Ukrainian websites to display a fake Cloudflare verification ClickFix lure:
134
Simon Kenin @k3yp0d.bsky.social · 12/09/2026
6/6 ref 2: www.group-ib.com/blog/tortois...
group-ib.com
Tortoiseshell: New Toolset and Operational Infrastructure Exposed
Group-IB Threat Intelligence performed enrichment and APT hunting based on recent public data about the Tortoiseshell APT group, leading to the discovery of new samples sharing similarities with known...
000
Simon Kenin @k3yp0d.bsky.social · 12/09/2026
5/6 This sample is most likely related to a new-ish cluster of activity tracked as: UNK_SmudgedSerpent/Obsidian Sandstorm/Yellow Mithras. NOT Mirage Kitten/Tortoiseshell. ref 1: www.proofpoint.com/us/blog/thre...
proofpoint.com
Crossed wires: a case study of Iranian espionage and attribution | Proofpoint US
Proofpoint would like to thank Josh Miller for his initial research on UNK_SmudgedSerpent and contribution to this report. Key findings Between June and August 2025,
100
Simon Kenin @k3yp0d.bsky.social · 12/09/2026
4/6 Bonus? node-helper.js cb657d93c76413f6e746a4c09484124c 0f31eebd6f6d51fadaeeb8bb6574faa1bc21beed 2a8fd58441cc78e38130e30823d2b986fbe0f55783f05f8c71f3e1ac696f9d4c
100
Simon Kenin @k3yp0d.bsky.social · 12/09/2026
3/6 Challenge (malware) installation tutorial: Tutorial.pdf f8394f05a912bbc11f77872afe0c61d0 30e53c577c57272fb061703597e59c39ef29d0f1 463ffcb75eb4ad186ed8e913e0f6d4d06f16ac4c8e9cfcf6fb8885573c1d0969
100
Simon Kenin @k3yp0d.bsky.social · 12/09/2026
2/6 app.js->requireAuth.js->node-helpers.js d50567bba003059f323ffa6e6a3953cd 8bd90b61c1c6e4b0b0ada8a4f490ff96df86b072 ae69f105967806eb5a339abc69676eb2646827c122c01eff2eb47e2dc7f22b40 C2: lifespotify[.]com
100
Simon Kenin @k3yp0d.bsky.social · 12/09/2026
1/6 🇮🇷🇮🇷🇮🇷 Spotify--iQ38-main.zip c3d0d3ac1b943978262d03559bf6ff72 c3c54ff44d07a79cb30274f654ef688a14f11896 49f827b2b04e19dff915443deeba961e87e6e37312c12b75fa3ad3bacc33891e ZIP archive containing PollCat/ChallNode payload.
100
Simon Kenin @k3yp0d.bsky.social · 20/08/2026
www.youtube.com/watch?v=H5HN...
000
Simon Kenin @k3yp0d.bsky.social · 19/08/2026
4/4 c8c29e6611fdfe32f224f9bded71092b bf0c50a5bfadaf221eb790ce6926156f maidsradar[.]com #CocoFix www.youtube.com/watch?v=6vYn...
youtube.com
O.T. Genasis - CoCo [Official Music Video]
YouTube video by O.T. Genasis
000
Simon Kenin @k3yp0d.bsky.social · 19/08/2026
3/4 more coco: dda8c04041d80b06432a5ff0991fba81 70f1ee21c691ebcb25489fd936d42d6b 94c71245e64a97c75e791e2c7bc29cd5 b5a5b35e1b22f2964d899a666396ccb9 c2a5e1ad7eb53aa103182c0dfdd8c6d5 f4eac58a8e1798bdcb789ca5060a52ca c1e074caf8c74c987dfa9cac27594e33 #CocoFix
100
Simon Kenin @k3yp0d.bsky.social · 19/08/2026
2/4 coco.exe samples: d3670a170c470c2d627bc22fead48d42 72ed906346075abff43b04436a8ca2c1 fcccfa352fca3ec8db54a79c4ee86511 e4386da971bd39e8246f728ba0e7fffc 426e4469a492fcd77eb98eb8dc84b52a 4584d0ea5851a4bb90830f41c6b00f98 dfd582f44ca3dd2bd400a8ff42a70581 #CocoFix
100
Simon Kenin @k3yp0d.bsky.social · 19/08/2026
1/4 Another day another ClickFix campaign, I call this one #CocoFix because it is dropping an 500mb+ sized executable named coco.exe Sample: app.any.run/tasks/a8b0d1...
121
Simon Kenin @k3yp0d.bsky.social · 22/07/2026
2/2 ref 2: www.microsoft.com/en-us/securi... ref 3: unit42.paloaltonetworks.com/tracking-ira...
microsoft.com
Peach Sandstorm deploys new custom Tickler malware in long-running intelligence gathering operations | Microsoft Security Blog
Between April and July 2024, Microsoft observed Iranian state-sponsored threat actor Peach Sandstorm deploying a new custom multi-stage backdoor, which we named Tickler.
000
Simon Kenin @k3yp0d.bsky.social · 22/07/2026
1/2 Old UNC1549 sample from 2023 VGAuth.dll 98a81af2a597b62866610d32d03421ff f70a1d87c05f42980cb0a8acaafb3309e7170bda f99a50bd0884d356bd1bf9f2642f813a9e7c9035c8db31de268cb8d2cd4fa0a4 c2: usph1ap0035.eastus2.cloudapp.azure[.]com ref1: cloud.google.com/blog/topics/...
cloud.google.com
When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors | Google Cloud Blog
Suspected Iran-nexus espionage activity targeting the aerospace, aviation and defense industries in Middle East countries.
110
Simon Kenin @k3yp0d.bsky.social · 09/07/2026
new ref: www.microsoft.com/en-us/securi...
microsoft.com
GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware | Microsoft Security Blog
GigaWiper is a destructive backdoor that combines multiple wiping and ransomware-like capabilities into a single operational platform. This blog analyzes how the malware incorporates code from several...
000
Simon Kenin @k3yp0d.bsky.social · 08/07/2026
190.2.147.198 BlueRabbit / GRAT / GigaWiper C2 ref: bsky.app/profile/k3yp...
111
Simon Kenin @k3yp0d.bsky.social · 16/06/2026
bsky.app/profile/k3yp...
000
Simon Kenin @k3yp0d.bsky.social · 16/06/2026
bsky.app/profile/k3yp...
000
Simon Kenin @k3yp0d.bsky.social · 16/06/2026
bsky.app/profile/k3yp...
000
Simon Kenin @k3yp0d.bsky.social · 16/06/2026
hunt.io/blog/ababil-...
100
Simon Kenin @k3yp0d.bsky.social · 15/06/2026
2/2 Network IOC: yemplayer[.]site microsoft.comi-site[.]website ref: securelist.com/ferocious-ki...
securelist.com
Ferocious Kitten: 6 years of covert surveillance in Iran
Ferocious Kitten is an APT group that since at least 2015 has been targeting Persian-speaking individuals who appear to be based in Iran.
001
Simon Kenin @k3yp0d.bsky.social · 15/06/2026
1/2 MarkiRAT/Ferocious Kitten from early 2026: 334d5e38774bd0289346231a92a444cf 0c57def86b9d0e9df50101f45243b7a3 3c1f7d9d157c38d17a44f62b6560d3b4 d66de5d6dbcb6f460ae6240de8b7aab0 610696d1d05099125258d25a661704ce db6bc0e947acba379e540349f74fc6ee b56a18df4daf038785891f33c3e89489
100
Simon Kenin @k3yp0d.bsky.social · 08/06/2026
www.youtube.com/watch?v=60Tj... all the lies that you told, did you believe in them?
youtube.com
SKELER - PALE LIGHT (Music Video)
YouTube video by PHONKmedia東京
000
Simon Kenin @k3yp0d.bsky.social · 06/06/2026
2/2 ref: research.jfrog.com/post/iron-wo...
research.jfrog.com
IronWorm: Shai-Hulud's rustier cousin | JFrog
In this article we present research on a malicious npm package that led us to IronWorm: a Rust-built infostealer that scrapes secrets from developer machines, hides behind an eBPF kernel rootkit, and ...
000
Simon Kenin @k3yp0d.bsky.social · 06/06/2026
1/2 IronWorm ELF Payload: 178d327d87243a6d937ea9f1e4bcb20e 7befd633f4744a436ef6d122381276c43401be3b 36abd242ddaa27f0160c539377a0e92cf781c1695137850acc87e3892b436d36
100
Simon Kenin @k3yp0d.bsky.social · 28/05/2026
bonus: 2nd price.py 3cc7b1f2f7a119e4367159ab2cb23b83 9b49dd2a36f028850ba810883a8e58bd7d2f2fbd 57636c0107baa6c3ba33700e6115d5beafdf35466fb5e5db20d4de60e7f78e05 C2: coinhar[.]io
000
Simon Kenin @k3yp0d.bsky.social · 28/05/2026
3/3 That python code was inside a GitHub repo zip file named BTC-ETH-main.zip a1f41e2ac7756aba35b31729d292369d 89ab23dc358d49d514c0590b0e291eb98fac68d8 450c4b2e8dee94d93063ec57555b44cfa6125d5cb8015d31aa199cea5f83f6e2 Uploaded to VT in January 2025
000
Simon Kenin @k3yp0d.bsky.social · 28/05/2026
2/3 Only this ticker has a check for OS 🧐 gmoocsoom[.]site This domain was already connected to DPRK activity in 2025 hunt.io/blog/sparkra...
hunt.io
Unmasking SparkRAT: Detection & macOS Campaign Insights
Explore SparkRAT detection tactics, macOS targeting, and insights into recent DPRK-linked campaigns with actionable research findings.
100
Simon Kenin @k3yp0d.bsky.social · 28/05/2026
1/3 Suspected old DPRK sample of Pressure Chollima (TraderTraitor, Mata, Jade Sleet, Slow Pisces, UNC4899) price.py f9a80cc1b5a40d29718dd2da5c7cef04 2d1c79722edba23a55231fbbc5725aeb566accd3 776393d5d063a32c6e77b90485e9f15bd92bd346becfe718bd84de1ae9199b48
200
Simon Kenin @k3yp0d.bsky.social · 28/05/2026
ref: bsky.app/profile/k3yp...
000
Simon Kenin @k3yp0d.bsky.social · 28/05/2026
cdn.prod.website-files.com/69944dd945f2...
200
Simon Kenin @k3yp0d.bsky.social · 28/05/2026
3/3 Possibly related to BLUERABBIT Wiper / GRAT bsky.app/profile/k3yp...
000
Simon Kenin @k3yp0d.bsky.social · 28/05/2026
2/3 Previous BLUEWIPE sample from 2025 x.com/cyb3rops/sta...
x.com
100
Simon Kenin @k3yp0d.bsky.social · 28/05/2026
1/3 New BLUEWIPE wiper sample uploaded from Ukraine? O_o 7c76e51390b0d2e2759fad5ccee2bc30 b91be21e984407529691edb1bfe3f97dd4a1ae24 db41e0da7ab3305be8d9720769c6950b4dc1c1984ef857d3310eb873a0fc7674
100
Simon Kenin @k3yp0d.bsky.social · 28/05/2026
profero.io/blog/war-bet... TAG-175 GigaWiper / BLUERABBIT a9dbe0025975e3fa764376a437043963 be1082aac756fbf3ad7f41c1bc5b9eec 62bcb76113ea745020f5e68c8ce9f283 fbc2f83b75f3602a281fec095068ea34
profero.io
The War Between Wars: How an IRGC Cyber Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire
An IRGC-directed persona sabotaged industrial refrigeration and staged a disk-wipe campaign at Israeli facilities during a ceasefire. How the operation unfolded, and how to find the actor before it re...
000
Simon Kenin @k3yp0d.bsky.social · 20/05/2026
k3yp0d.blogspot.com/2026/05/the-...
k3yp0d.blogspot.com
The Water Is So Muddy That You Can’t See Clearly The Big Picture
Overview: This post is long overdue and unlike most of my posts, this is not a technical post, but rather a high level, strategical post, al...
000
Simon Kenin @k3yp0d.bsky.social · 01/05/2026
harfanglab.io/insidethelab...
harfanglab.io
RedKitten: AI-accelerated campaign targeting Iranian protests
Identifier: TRR260101. Summary RedKitten is a newly identified campaign targeting Iranian interests, likely including non-governmental organizations and individuals involved in documenting recent huma...
000
Simon Kenin @k3yp0d.bsky.social · 30/04/2026
profero.io/blog/windows... www.gov.il/BlobFolder/r... IOC: www.gov.il/BlobFolder/r...
profero.io
WindowsAudit Backdoor: Inside a .NET RAT That Hides in Discord
Profero IRT reverse engineered a .NET 8 RAT named WindowsAudit.exe recovered from a victim host in April 2026. It uses Discord as primary C2, runs as SYSTEM, tears down EDR in Safe Mode, and ships a f...
000
Simon Kenin @k3yp0d.bsky.social · 09/12/2025
If you are hiring full remote, you must read this. DPRK IT workers is a much bigger problem than you think, those are today's spies that infiltrate multiple organizations simultaneously without the risk of being caught. any.run/cybersecurit...
any.run
How We Caught Lazarus's IT Workers Scheme Live on Camera
See how Lazarus Group's IT workers scheme was exposed on a live camera using real-time monitoring inside ANY.RUN’s sandbox.
000
Simon Kenin @k3yp0d.bsky.social · 09/12/2025
2/2 410f5add77c00714d1e214495c406dc2 6dadafaa55728ef8bd27a0e802dfeebb ref: www.koi.ai/blog/4-milli...
koi.ai
4.3 Million Browsers Infected: Inside ShadyPanda's 7-Year Malware Campaign | Koi Blog
000
Simon Kenin @k3yp0d.bsky.social · 09/12/2025
1/2 ShadyPanda extension samples: e9975e39b87a0369dba21dcc7a4dcd56 b4a828b6ea8f0faaf9a2cdbc5b7a8241 5c56346e09de3aef10d8df6b292df9b3 491518101c265a7a79040ea148bc7ae7 6619beef592118fa90dc67b103eb6d58 58a6c9a2125858e828191e51d9f30e4f
100
Reposted by Simon Kenin
ESET Research @esetresearch.bsky.social · 02/12/2025
#ESETresearch discovered a new #MuddyWater campaign targeting critical infrastructure in 🇮🇱 Israel and 🇪🇬 Egypt, using a new backdoor – MuddyViper – and a variety of post-compromise tools www.welivesecurity.com/en/eset-rese... 1/7
welivesecurity.com
MuddyWater: Snakes by the riverbank
MuddyWater targets critical infrastructure in Israel and Egypt, relying on custom malware, improved tactics, and a predictable playbook.
176
Simon Kenin @k3yp0d.bsky.social · 26/11/2025
UNC5203
000
Simon Kenin @k3yp0d.bsky.social · 18/11/2025
govextra.gov.il/national-dig... credit where credit is due, part 2
govextra.gov.il
SpearSpecter
Unmasking Iran’s IRGC Cyber Operations Targeting High-Profile Individuals The SpearSpecter campaign linked to Iran’s IRGC / APT42 used social engineering and the TAMECAT backdoor to infiltrate high-v...
000
Simon Kenin @k3yp0d.bsky.social · 18/11/2025
www.youtube.com/watch?v=4iYA...
youtube.com
שם טוב האבי 2 | הסרט המלא ⭐
YouTube video by כאן | דיגיטל - תאגיד השידור הישראלי
000
Simon Kenin @k3yp0d.bsky.social · 18/11/2025
cloud.google.com/blog/topics/...
cloud.google.com
Frontline Intelligence: Analysis of UNC1549 TTPs, Custom Tools, and Malware Targeting the Aerospace and Defense Ecosystem | Google Cloud Blog
Tactics, techniques and procedures we discovered during incident response investigations into UNC1549 activity.
000
Simon Kenin @k3yp0d.bsky.social · 16/11/2025
4/4 VIBE attribution to Handala because of similarities in TTPs and similarities to their HEAVYGRAM malware. Ref: doublepulsar.com/handala-atte... I don't need to reverse this shit to know... 🤡
doublepulsar.com
Handala attempts a supply chain hack via ReutOne
During the week, Handala — a group painfully in love with Israel, tried a forward supply chain attack.
100