Selected earlier work
Writing from before this site existed, kept because the thread runs through to what I work on now.
A three-part series I wrote at FireEye in August 2013, on how little skill it took to assemble a working botnet out of commodity malware. It ran on the company’s executive blog and was picked up in the trade press at the time.
FireEye no longer exists as a brand. Its products business was merged with McAfee Enterprise and relaunched as Trellix in 2022, and the original posts have gone from the web, so what follows are archive captures.
I have kept them here for one reason. The third post ends with something I found by accident: my research botnet had exactly one member, a virtual machine on my own desk, and within a day antivirus vendors around the world were connecting to its command-and-control server. They were mining public sample uploads to discover live infrastructure, which meant the defenders’ pipeline had an intake nobody controlled. The Botnet With One Member returns to that finding thirteen years later, and argues it mattered more than I understood at the time.
- Aug 2013 FireEye Teaching Old Malware New Tricks Why vintage families like ZeuS and Carberp still had a bigger bite than anyone assumed, and how much of it walked straight past the defences that were supposed to have retired it.
- Aug 2013 FireEye Cybercriminal Intent: How to Build Your Own Botnet in Less Than 15 Minutes A step-by-step account of how cheap and how quick the assembly had become, written to show defenders what they were actually up against.
- Aug 2013 FireEye Thinking Outside the Sandbox The accident at the end of the series: antivirus vendors were mining public sample uploads to find command-and-control servers, which meant their pipeline could be fed.