Senior Threat Intelligence Researcher at Acronis TRU, tracking APT campaigns across Asia with a focus on implant engineering, infrastructure hunting, and malware reverse engineering.
Previously at Seqrite Labs. Senior Judge at Trace Labs. Independent contracts for malware analysis training and Windows incident work.
01Services
- Independent contracts on training, malware analysis, reverse engineering
- Independent contracts on defensive research and incident reports on Windows malware
- Independent contracts on the development of Windows software
02Notable Works
- ZOHOMURK, Mustang Panda’s Zoho WorkDrive C2 abuse, three implant families, coordinated CERT‑In takedown (Acronis TRU)
- PATCHCORD, Windows x64 implant targeting Afghan telecom providers, Go‑based C2 (Acronis TRU)
- Khmer Shadow, NightForge loader & Havoc C2 against Cambodian government targets (Acronis TRU)
- CRESCENTHARVEST, Iranian cyberespionage targeting protesters (Acronis TRU)
- LOTUSLITE, C++ backdoor with banking‑sector lures (Acronis TRU)
- SPLITWING, Cross‑platform infostealer targeting military drone operators (Acronis TRU)
- Silent Lynx, YoroTrooper‑linked Central Asian campaign (Seqrite Labs)
- Dissecting Exfiltrator‑22, Hunting the malware developer
- Winver, Reverse‑engineering Patchwork APT’s recent Golang implant
03Talks & Trainings
- 2026
ROOTCON upcoming
- 2026
Virus Bulletin upcoming
- 2026
Black Hat MEA training · upcoming
- 2026
c0c0n, Kochi — Threat Tradecraft: Infrastructure Hunting & Malware Analysis training
- 2026
VULNCON, Bangalore —
Ballot, Bytes, and Backdoors: Chinese APT Election Interference from the Balkans to South Asia
- 2026
RISEx, Frankfurt —
NewsJacking: Tracking Three Months of Uncovered APT Operations Disguised as Global Headlines
- 2026
FIRST TC, Bangalore —
Two Countries and One Lie: Unmasking a Misattributed APT from Baku to Dushanbe
- 2025
AVAR —
Operation DRAGONCLONE: Chinese Telecommunication Industry Targeted via VELETRIX & VShell Malware
- 2025
Virus Bulletin —
Silent Lynx: Uncovering a Cyber Espionage Campaign in Central Asia
- 2025
Positive Hack Talks, Jakarta —
UNG0002: Regional Threat Operations Tracked Across Multiple Asian Jurisdictions
- 2025
FIRSTCON —
Uncovering the Whispers of an APT Targeting Specific Industries in South Asia
- 2024
AVAR — The Rise and Fall of Golang Malware
- 2021
ROOTCON 15 —
Buzzard: Crafting Your Post‑Exploitation Framework Against Odds
04Little Milestone
- Referenced by Kazakhstan national CERT (KZ-CERT) for APT campaign discovery in the Central Asian region
- Discovered novel implant families attributed to Chinese, Central Asian, and Iranian APTs: LOTUSLITE, ZOHOMURK, VELETRIX, CRESCENTHARVEST
- Coordinated with CERT-In government scientists to take down a live Mustang Panda campaign targeting Indian government entities
- Collaborated with VirusTotal on threat intelligence practitioner research and hunting workflows
- Discovered an undocumented callback mechanism in the RegisterWaitForInputIdle API and published a shellcode execution POC, before MSDN documentation existed for it
- Forced Mustang Panda to rotate their payload delivery chain, from ZIP to CHM to VHDX, through sustained public disclosure
05Features & Press
- 2026
- 2026
- 2026
- 2026
- 2026
- 2026
- 2026
- 2026
- 2026
- 2026
- 2026
- 2026
- 2025
- 2025
- 2025
- 2025
- 2025
- 2025
- 2024
- 2020