sm. Simon Mullis

Selected earlier work

Writing from before this site existed, kept because the thread runs through to what I work on now.

A three-part series I wrote at FireEye in August 2013, on how little skill it took to assemble a working botnet out of commodity malware. It ran on the company’s executive blog and was picked up in the trade press at the time.

FireEye no longer exists as a brand. Its products business was merged with McAfee Enterprise and relaunched as Trellix in 2022, and the original posts have gone from the web, so what follows are archive captures.

I have kept them here for one reason. The third post ends with something I found by accident: my research botnet had exactly one member, a virtual machine on my own desk, and within a day antivirus vendors around the world were connecting to its command-and-control server. They were mining public sample uploads to discover live infrastructure, which meant the defenders’ pipeline had an intake nobody controlled. The Botnet With One Member returns to that finding thirteen years later, and argues it mattered more than I understood at the time.