SentinelLabs Logo RGB WhitePurp
ABOUT
CVE DATABASE
CONTACT
VISIT SENTINELONE.COM

Juan Andrés Guerrero-Saade

Juan Andrés is Executive Director for Intelligence and Security Research at SentinelOne—overseeing intelligence production across Threat Discovery and Response and leading SentinelLabs—and Distinguished Resident Fellow for Threat Intelligence at the Johns Hopkins SAIS Alperovitch Institute. Before joining SentinelOne, JAGS led multiple threat intelligence teams at Google, Chronicle, was a Principal Security Researcher at GReAT focusing on targeted attacks, and served as Senior Cybersecurity and National Security Advisor to the Government of Ecuador. In 2023, JAGS was presented with a Presidential Volunteer Service Award for furthering U.S. cyber preparedness. His research work is the subject of two permanent exhibits at the International Spy Museum in Washington, DC.
Acid Pour Bg
labs
Adversary

AcidPour | New Embedded Wiper Variant of AcidRain Appears in Ukraine

Juan Andrés Guerrero-Saade & Tom Hegel / March 21, 2024

SentinelLABS has discovered a novel malware variant of AcidRain that could be targeting telecoms networks in Ukraine.

Read More
sentinelone

3CX SmoothOperator | 3CXDesktopApp in Supply Chain Attack

From the Front Lines | 9 minute read
Read More >
The Life And Times Of Sysinternals 3
labs
LABScon

The Life and Times of SysInternals | How One Developer Changed the Face of Malware Analysis

Juan Andrés Guerrero-Saade / March 29, 2023

Mark Russinovich, founder of SysInternals, explores the history and development of one of the security industry's most essential toolkits.

Read More
The Mystery Of Metador An Unattributed Threat Hiding In Telcos ISPs And Universities 3
labs
Advanced Persistent Threat

The Mystery of Metador | An Unattributed Threat Hiding in Telcos, ISPs, and Universities

Juan Andrés Guerrero-Saade / September 22, 2022

An elusive adversary is attacking high-value targets with impunity using novel malware frameworks and custom-built backdoors.

Read More
CrateDepression Rust Supply Chain Attack Infects Cloud CI Pipelines With Go Malware 1
labs
Crimeware

CrateDepression | Rust Supply-Chain Attack Infects Cloud CI Pipelines with Go Malware

Juan Andrés Guerrero-Saade / May 19, 2022

Software developers using GitLab CI are being targeted with malware through a typosquatting attack, putting downstream users at risk.

Read More
AcidRain A Modem Wiper Rains Down On Europe 2
labs
Adversary

AcidRain | A Modem Wiper Rains Down on Europe

Juan Andrés Guerrero-Saade / March 31, 2022

As the most impactful cyber attack of the Ukrainian invasion gets downplayed, SentinelLabs uncovers a more plausible explanation.

Read More
Hermetic Wiper Ukraine Is Under Attack 4
labs
Advanced Persistent Threat

HermeticWiper | New Destructive Malware Used In Cyber Attacks on Ukraine

Juan Andrés Guerrero-Saade / February 23, 2022

A new malware is attacking Ukrainian organizations and erasing Windows devices. In this early analysis, we provide technical details, IOCS and hunting rules.

Read More
Hacktivism And State Sponsored Knock Offs Attributing Deceptive Hack And Leak Operations 3
labs
Advanced Persistent Threat

Hacktivism and State-Sponsored Knock-Offs | Attributing Deceptive Hack-and-Leak Operations

Juan Andrés Guerrero-Saade / January 27, 2022

Are there still real hacktivists out there or are they all a cover for state-sponsored operations?

Read More
AlphaGolang A Step By Step Go Malware Reversing Methodology For IDA Pro 4
labs
Security Research

AlphaGolang | A Step-by-Step Go Malware Reversing Methodology for IDA Pro

Juan Andrés Guerrero-Saade / October 21, 2021

SentinelLabs sets off to dispel the myth that Go malware is hard to reverse engineer. This suite of IDApython scripts will set you well on your way

Read More
EGoManiac An Unscrupulous Turkish Nexus Threat Actor 3
labs
Advanced Persistent Threat

EGoManiac | An Unscrupulous Turkish-Nexus Threat Actor

Juan Andrés Guerrero-Saade / September 8, 2021

EGoManiac is a threat actor willing to spy on friend and foe and entrap journalists without compunction. Read our groundbreaking research.

Read More
Previous
1 2
Next

SentinelLabs

In the era of interconnectivity, when markets, geographies, and jurisdictions merge in the melting pot of the digital domain, the perils of the threat ecosystem become unparalleled. Crimeware families achieve an unparalleled level of technical sophistication, APT groups are competing in fully-fledged cyber warfare, while once decentralized and scattered threat actors are forming adamant alliances of operating as elite corporate espionage teams.

Recent Posts

  • FreeDrain Unmasked | Uncovering an Industrial-Scale Crypto Theft Network
    FreeDrain Unmasked | Uncovering an Industrial-Scale Crypto Theft Network
    May 8, 2025
  • Top Tier Target | What It Takes to Defend a Cybersecurity Company from Today’s Adversaries
    Top Tier Target | What It Takes to Defend a Cybersecurity Company from Today’s Adversaries
    April 28, 2025
  • AkiraBot | AI-Powered Bot Bypasses CAPTCHAs, Spams Websites At Scale
    AkiraBot | AI-Powered Bot Bypasses CAPTCHAs, Spams Websites At Scale
    April 9, 2025

Sign Up

Get notified when we post new content.

Thanks! Keep an eye out for new content!

  • Twitter
  • LinkedIn
©2025 SentinelOne, All Rights Reserved.