Johnnie malware family
Johnnie is a malware family tracked by MalwareAnalyzer by Cyble across 2 publicly analyzed samples. First seen 2026-08-16, most recently 2026-08-20. Observed ATT&CK techniques include T1071.001.
Corpus statistics
- Publicly analyzed samples: 2
- First seen: 2026-08-16
- Last seen: 2026-08-20
- Verdicts: malicious 2
- File types: pe 2
ATT&CK techniques used by Johnnie
- T1071.001 - 1 sample
Recent Johnnie samples
- 24f8f4ab909710030ec5522c5bc2d6a94b4b16744cf39f5c55e66bd0e12fbc47 - malicious (2026-08-20)
- 4485e638e43e37eb05c7ce5dcc795b1d9c80efd4020d8cfad1ff4cf68e116eb2 - malicious (2026-08-16)
Frequently asked about Johnnie
- What is Johnnie?
- Johnnie is a malware family tracked by MalwareAnalyzer by Cyble across 2 publicly analyzed samples. First seen 2026-08-16, most recently 2026-08-20. Observed ATT&CK techniques include T1071.001.
- How many Johnnie samples have been analyzed?
- MalwareAnalyzer by Cyble holds 2 publicly analyzed samples attributed to Johnnie, first seen 2026-08-16 and most recently 2026-08-20. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does Johnnie use?
- Across our Johnnie samples the most frequently observed techniques are T1071.001 (1). Counts are the number of analyzed samples in which each technique was observed.
- What file types does Johnnie use?
- Johnnie samples in this corpus are distributed as pe (2).
- Is Johnnie malicious?
- 2 of 2 analyzed Johnnie samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends