A globe with malware networks, severed connections, and research observation paths

Amadey and StealC: Malware-as-a-Service Unavailable

C2 mapping, malware emulation, and infection telemetry supporting the Amadey and StealC disruption.

Research article · June 24, 2026
Compromised Android TV boxes connected to botnet nodes and a research observation server

Into the Vo1d: Hunting a Botnet Hidden in TV Boxes

A BSides Lisbon talk connecting malware analysis, DNS intelligence, and sinkhole telemetry in an Android TV botnet investigation.

Talk · November 14, 2025
Credential records flowing from a laptop to a Telegram paper-plane symbol

Exfiltration over Telegram Bots: Skidding Infostealer Logs

An investigation of Telegram bot exfiltration, infostealer log formats, and the visibility those records provide.

Research article · October 16, 2024
A metallic spider on a chip beside encrypted fragments and exposed circuit paths

Hunting PrivateLoader: The Malware Behind InstallsKey PPI Service

Tracing changes in PrivateLoader protocols and string obfuscation, with YARA and Suricata detection.

Research article · February 27, 2024
A blue-lit keyboard with identity records flowing through email to connected devices

Data Insights on AgentTesla and OriginLogger Victims

Configuration and infection-data analysis of AgentTesla and OriginLogger, including their exfiltration methods.

Research article · January 9, 2024
A malicious email linked to proxy nodes, a processor, and mining coins

Tofsee Botnet: Proxying and Mining

Investigating the proxying, spam, and cryptocurrency-mining activity of the modular Tofsee botnet.

Research article · March 28, 2023
A bird escaping a cage beside layers opening to reveal a circuit core

Unpacking Colibri Loader: A Russian APT-linked Campaign

A Colibri Loader unpacking walkthrough covering anti-analysis techniques, string decryption, and YARA detection.

Research article · November 30, 2022
A loader distributing different payloads through branching connections

Tracking PrivateLoader: Malware Distribution Service

Tracking PrivateLoader delivery chains and identifying 30 malware families in the collected payloads.

Research article · August 31, 2022
Two memory stacks combining to unlock hidden data inspected through a magnifying glass

Decrypting and Hunting PrivateLoader

Building a PrivateLoader string decryptor and YARA rule from a stack-based XOR pattern.

Technical walkthrough · June 6, 2022 · 4 min read
SMS-linked phones beside a map highlighting Europe and Australia

FluBot Persists: Infecting Europe and Australia

A historical investigation of FluBot distribution, infection telemetry, and its domain-generation algorithm.

Research article · February 4, 2022
A phone with a hidden malicious chip beside factory-packaged connected devices

Backdoors Pre-Installed on Cheap Android Devices

Sinkhole observations of pre-installed Android threats and insecure device-update mechanisms.

Research article · April 28, 2020
Phone applications linked through an embedded chip to advertisements and many devices

Fraudulent Ads SDK Installed on 15 Million Android Devices

An Android advertising SDK investigation, with a historical appendix of sample hashes, package names, and domains.

Research article · March 8, 2019