Senior threat researcher at Bitsight, with experience since 2018 in malware analysis, reverse engineering, and botnet tracking. I develop malware emulators and detection signatures, automate infrastructure research, and analyze large datasets to identify compromised systems and exposed credentials. I share findings, indicators, and detection tools through publications, conference talks, and community contributions.

Experience

Senior Threat Researcher · Bitsight

February 2022 - Present · Lisbon, Portugal · Remote

  • Research malware including Vo1d, Amadey, StealC, and Vidar through reverse engineering, botnet tracking, and command-and-control (C2) infrastructure analysis.
  • Develop botnet trackers and emulators to monitor C2 activity and malware distribution campaigns.
  • Develop network, file, and memory detection signatures, and publish technical research on malware behavior and infrastructure.
  • Analyze and enrich NetFlow data, passive DNS records, and infostealer logs with Apache Spark on Amazon EMR to identify compromised systems and exposed credentials.

Threat Researcher · Bitsight

January 2020 - January 2022 · Lisbon, Portugal · Remote

  • Reverse engineered malware including FluBot, IcedID, and TrickBot; developed botnet trackers, emulators, and detection signatures to monitor C2 infrastructure and distribution campaigns.
  • Automated domain hunting, classification, and clustering with Python.

Junior Threat Researcher · Bitsight

January 2018 - December 2019 · Lisbon, Portugal

  • Discovered and classified botnet C2 domains using open-source intelligence, malware analysis, and reverse engineering.
  • Wrote Python scripts and network detection signatures to support threat research.

Technical skills

  • Malware analysis and reverse engineering: Ghidra, IDA, x64dbg, JADX.
  • Botnet and infrastructure research: C2 protocol emulation; OSINT; domain hunting, classification, and clustering.
  • Detection development and network analysis: network, file, and memory signatures; YARA, Suricata, Wireshark.
  • Research automation and large-scale data processing: Python, PySpark, SQL, Bash, regular expressions; Apache Spark on Amazon EMR, OpenSearch.
  • Additional programming and development tools: C++, assembly, Java, JavaScript; Git, Docker, VS Code.

Selected research and speaking

  • Amadey and StealC: Malware-as-a-Service Unavailable · June 2026. Bitsight TRACE contributed C2 infrastructure mapping, indicators, and infection telemetry to a disruption led by Europol and Microsoft. The team’s publication documents sample hunting, configuration extraction, bot emulation, and published YARA and Suricata rules.
  • Into the Vo1d: Hunting a Botnet Hidden in TV Boxes · BSides Lisbon, November 2025. Presented our team’s investigation of an Android TV botnet, connecting malware analysis, DNS intelligence, sinkhole telemetry, and collaboration between researchers. Recording.
  • Exfiltration over Telegram Bots · October 2024. Authored a study of credential exfiltration using a team dataset of about five million logs from approximately 1,800 bots, with parsing covering 27 infostealer families. These were historical log records, mostly from 2022 onward, rather than a count of unique victims.

Community contributions: Malware OSINT contributions to abuse.ch under andretavare5 and Bitsight.

Full research archive

Education

B.Sc. + M.Sc. in Computer Science and Engineering
Instituto Superior Técnico, Universidade de Lisboa · Lisbon, Portugal
September 2012 - November 2017
Specializations in Cyber Security and Software Engineering. Erasmus exchange at the University of Amsterdam.

Training and conferences

Languages and interests

Languages: Portuguese, English, Spanish.

Interests: InfoSec, FOSS, reading, calisthenics, travel, climbing, outdoors, guitar, casual gaming, sustainability, and volunteering.