About
This blog shares simple and clear insights about malware analysis and threat intelligence, focusing on real cases, attacker tools, and research findings.
π $whoami
I am a Senior Threat Intelligence Analyst with experience in tracking advanced malware and APT groups. I have worked with international law enforcement on joint operations and presented multiple research findings at cybersecurity conferences.
π€ My Talks
VirusBulletin 2024 (Dublin) β Origins of a Logger β Agent Tesla
How Agent Tesla and Origin Logger were built and evolved.X33FCON 2023 (Gdynia) β Wizard Spider: Operational Environment
Shared how Wizard Spider connects with Trickbot, Ryuk, Lockbit, and FIN7.VirusBulletin 2023 (London) β The Evolution of TA551
Explained how TA551 sells access to ransomware groups like Conti and distributes BEC e-mails with Mailchecker.BOTCONF 2023 (Strasbourg) β TA551βs Supply Chain Attack
Showed how TA551 attacked a global IT training and certification company.C4DT β EPFL 2023 (Switzerland) β TA551βs Supply Chain Attack
Gave a talk about TA551βs ongoing supply chain campaign.Global Initiative Podcast 2023 (London) β Deep Dive: Exploring Organized Crime
Talked about the rise and fall of the Conti ransomware group.BOTCONF 2022 (Nantes) β Behind the Scenes of QBot
Presented deep research on the QBot malware infrastructure.
π Achievements
- π₯ Locked Shields 2025 (NATO) β 2nd place representing TΓΌrkiye (Malware & DFIR team)
- π₯ Locked Shields 2024 (NATO) β 3rd place representing TΓΌrkiye (Malware & DFIR team)
- π Certified Threat Intelligence Analyst (EC-Council)