Senior threat researcher at Bitsight, with experience since 2018 in malware analysis, reverse engineering, and botnet tracking. I develop malware emulators and detection signatures, automate infrastructure research, and analyze large datasets to identify compromised systems and exposed credentials. I share findings, indicators, and detection tools through publications, conference talks, and community contributions.
Experience
Senior Threat Researcher · Bitsight
February 2022 - Present · Lisbon, Portugal · Remote
- Research malware including Vo1d, Amadey, StealC, and Vidar through reverse engineering, botnet tracking, and command-and-control (C2) infrastructure analysis.
- Develop botnet trackers and emulators to monitor C2 activity and malware distribution campaigns.
- Develop network, file, and memory detection signatures, and publish technical research on malware behavior and infrastructure.
- Analyze and enrich NetFlow data, passive DNS records, and infostealer logs with Apache Spark on Amazon EMR to identify compromised systems and exposed credentials.
Threat Researcher · Bitsight
January 2020 - January 2022 · Lisbon, Portugal · Remote
- Reverse engineered malware including FluBot, IcedID, and TrickBot; developed botnet trackers, emulators, and detection signatures to monitor C2 infrastructure and distribution campaigns.
- Automated domain hunting, classification, and clustering with Python.
Junior Threat Researcher · Bitsight
January 2018 - December 2019 · Lisbon, Portugal
- Discovered and classified botnet C2 domains using open-source intelligence, malware analysis, and reverse engineering.
- Wrote Python scripts and network detection signatures to support threat research.
Technical skills
- Malware analysis and reverse engineering: Ghidra, IDA, x64dbg, JADX.
- Botnet and infrastructure research: C2 protocol emulation; OSINT; domain hunting, classification, and clustering.
- Detection development and network analysis: network, file, and memory signatures; YARA, Suricata, Wireshark.
- Research automation and large-scale data processing: Python, PySpark, SQL, Bash, regular expressions; Apache Spark on Amazon EMR, OpenSearch.
- Additional programming and development tools: C++, assembly, Java, JavaScript; Git, Docker, VS Code.
Selected research and speaking
- Amadey and StealC: Malware-as-a-Service Unavailable · June 2026. Bitsight TRACE contributed C2 infrastructure mapping, indicators, and infection telemetry to a disruption led by Europol and Microsoft. The team’s publication documents sample hunting, configuration extraction, bot emulation, and published YARA and Suricata rules.
- Into the Vo1d: Hunting a Botnet Hidden in TV Boxes · BSides Lisbon, November 2025. Presented our team’s investigation of an Android TV botnet, connecting malware analysis, DNS intelligence, sinkhole telemetry, and collaboration between researchers. Recording.
- Exfiltration over Telegram Bots · October 2024. Authored a study of credential exfiltration using a team dataset of about five million logs from approximately 1,800 bots, with parsing covering 27 infostealer families. These were historical log records, mostly from 2022 onward, rather than a count of unique victims.
Community contributions: Malware OSINT contributions to abuse.ch under andretavare5 and Bitsight.
Education
B.Sc. + M.Sc. in Computer Science and Engineering
Instituto Superior Técnico, Universidade de Lisboa · Lisbon, Portugal
September 2012 - November 2017
Specializations in Cyber Security and Software Engineering. Erasmus exchange at the University of Amsterdam.
Training and conferences
- Introduction to Malware Binary Triage · Invoke RE.
- Targeted Malware Reverse Engineering and Advanced Malware Reverse Engineering with Ghidra · Kaspersky.
- Zero 2 Automated: The Advanced Malware Analysis Course · 0ffset Training Solutions.
- Conference attendance: Botconf, 2018-2026; Underground Economy, 2023/24/26.
Languages and interests
Languages: Portuguese, English, Spanish.
Interests: InfoSec, FOSS, reading, calisthenics, travel, climbing, outdoors, guitar, casual gaming, sustainability, and volunteering.