A globe with malware networks, severed connections, and research observation paths

Amadey and StealC: Malware-as-a-Service Unavailable

C2 mapping, malware emulation, and infection telemetry supporting the Amadey and StealC disruption.

Research article · June 24, 2026
Credential records flowing from a laptop to a Telegram paper-plane symbol

Exfiltration over Telegram Bots: Skidding Infostealer Logs

An investigation of Telegram bot exfiltration, infostealer log formats, and the visibility those records provide.

Research article · October 16, 2024
A blue-lit keyboard with identity records flowing through email to connected devices

Data Insights on AgentTesla and OriginLogger Victims

Configuration and infection-data analysis of AgentTesla and OriginLogger, including their exfiltration methods.

Research article · January 9, 2024