I’m a cybersecurity and threat intelligence analyst focused on cybercrime, malware analysis, reverse engineering, adversary tradecraft, and APT activity. My work spans threat actor and infrastructure tracking, malware and code analysis, software supply chain threats, and emerging attacker techniques.
I track threat actors, infrastructure, and campaign shifts, analyze malware and intrusion chains, develop detection logic for threat hunting, and turn technical investigations into high-signal detections, actionable intelligence, research, and tooling that defenders can actually use.
Focus Areas
- 🕵️ Cybercrime research — Tracking financially motivated threat activity, criminal ecosystems, infrastructure, tooling, campaigns, and evolving tradecraft
- 🎯 APT activity — Tracking state-linked threat groups, targeting priorities, operational patterns, campaign evolution, and shifts in adversary behavior
- 🔬 Malware and code analysis — Reverse engineering malicious code, tracing payload behavior and intrusion chains, and understanding how campaigns operate at scale
- 🛡️ Detections — Turning investigations into hunting logic, detections, mitigations, and practical defensive guidance
- 📦 Software supply chain and open source security — Investigating malicious packages, typosquatting, dependency confusion, extension abuse, developer compromise, and supply chain intrusions across npm, PyPI, Go Modules, GitHub, RubyGems, Maven Central, crates.io, NuGet, Packagist, Chrome, Firefox, Edge, VS Code, Open VSX, and related ecosystems
- 🧪 Emerging abuse patterns — Tracking how threat actors exploit automation, CI/CD workflows, AI-adjacent environments, and other evolving technologies
Journey
- 🔎 Always researching — My North Star is to follow the evidence and turn investigations into detections that help defenders
Senior Threat Intelligence Analyst at Socket (2024–2026) — Focused on software supply chain threats, malicious open source packages and extensions, developer-targeted attacks, malware analysis, and adversary research
Recorded Future (a Mastercard
company) (2018–2023) — 5 years across the ARMOR (Advanced Reversing, Malware, Operations & Reconnaissance) and ACE (Advanced Cybercrime & Engagements) teams
SANS Technology Institute alum — Applied Cybersecurity (ACS) Program (certified GCIA, GCIH, GSEC, GFACT)
Member of InfraGard, a public-private partnership with the FBI; participating in information-sharing and chapter activities focused on U.S. critical infrastructure security
Earlier in my career, I worked on investigations and programs aimed at mitigating human trafficking, corruption, and labor abuses at the United Nations, the American Bar Association, and the International Labor Rights Forum. That path wasn’t linear, but it shaped how I work: investigator first, evidence-driven always, and focused on turning complex problems into something useful for defenders.
Research, Writing, and Speaking
I publish research and speak about cybercrime, APT activity, adversary tradecraft, malware analysis and reverse engineering, software supply chain attacks, and malicious packages. My work ranges from deep technical analysis to practical defensive guidance for security teams, developers, and the broader security community.
Research I contributed to has been cited in MITRE ATT&CK entries including Supply Chain Compromise (T1195.001), Contagious Interview (G1052), BeaverTail (S1246), HexEval Loader (S1249), XORIndex Loader (S1248), and GlassWorm (S9010). Selected work is available in my Publications and Presentations sections.
🗣️ For anyone wondering, and many understandably do, Kirill is pronounced “key-reel” (two words put together: key + reel).
