Wednesday, 22 October 2025

AMTSO 2025 - Rethinking AV Testing in the Age of AI


Last week’s AMTSO conference in Lisbon was a fantastic experience -- great discussions, sharp questions, and an engaged audience! πŸ€“ 

In my talk (video is now available on YouTube https://www.youtube.com/watch?v=uQagBMFVCjE), I explored how traditional antivirus testing methodologies are falling behind in the era of AI-driven cyber threats. We revisited our earlier work on Reinforcement Learning–powered ransomware and connected it to recent developments, including LLM-powered attacks such as APT28’s LAMEHUG operation. The key takeaway: malware testing must evolve to assess adaptive, AI-enabled threats that can modify their tactics in real time.

I’m grateful to the AMTSO community for the opportunity to share these insights and to everyone who joined the discussion on rethinking AV testing in the age of intelligent malware. Looking forward to continued collaboration on building the next generation of testing standards.

Tuesday, 1 July 2025

AI-Powered Malware Analysis training (Black Hat Europe 2025)






I'm thrilled to share that my newly revamped Malware Analysis course, now enhanced with AI/GenAI-powered techniques, has been officially selected for the Black Hat Europe 2025 program!

The course will be delivered as a two-day training, focusing on how AI can improve reverse engineering, threat hunting, and behavioral analysis workflows.

Looking forward to engaging with fellow researchers, analysts, and defenders this December in London! πŸ˜€

Link: https://www.blackhat.com/eu-25/training/schedule/index.html#ai-powered-malware-analysis-46242


Monday, 30 June 2025

The Attribution Story of WhisperGate: An Academic Perspective


I'm excited to share that Anders Carlsson and I will be presenting our talk, "The Attribution Story of WhisperGate: An Academic Perspective," at the VB2025 conference in Berlin, 24–26 September 2025. πŸ€“ 

In this talk, we'll explore how AI/GenAI can assist in tackling the complex challenge of cyberattack attribution, using the WhisperGate incident as a case study.

WhisperGate is a destructive malware campaign executed on 13 January 2022 against the government infrastructure of Ukraine. It was attributed to the Russian state-sponsored threat actor linked explicitly to the Ember Bear group by CrowdStrike on 30 March 2022 [1] and to Cadet Blizzard by Microsoft in April 2022 [2]. It was associated with Russia's Main Intelligence Directorate of the General Staff (GRU). These APT group(s) have never been seen before, and it was unclear which GRU unit this campaign was associated with. ESET, in its turn, attributed the majority of wiper attacks against Ukraine in 2022 to Sandworm, another GRU-associated APT group (Unit 74455) [3], "with varying degrees of confidence" [4].

Only two years later, in September 2024, Maryland's Grand Jury unsealed a superseding indictment [5] against five members of GRU's Unit 29155 (a.k.a. Ember Bear) and one previously charged, in June 2024, Russian civilian Amin Stigal [6] for a cyber operation called WhisperGate [7] against the Ukrainian Government services and its allies in the US and Europe – at least 26 NATO countries. It was the first time GRU's Unit 29155 was mentioned as a cyber actor.

According to Bellingcat [8], this unit is famous for its assassination and sabotage operations abroad rather than cyberattacks, such as the Salisbury Poisonings – a failed assassination attempt on Sergei Skripal, a former Russian military officer and double agent for British intelligence, using a nerve agent. The attack, which also poisoned his daughter Yulia, took place in Salisbury, England, on 4 March 2018. [9]

Now that WhisperGate's attribution is well-established, we can retrospectively apply and compare different attribution approaches – manual analysis, traditional supervised machine learning classification, and LLM-powered attribution – to evaluate their effectiveness and determine which categories of Indicators of Compromise (IoCs) have the most significant impact on correct attribution decisions.


References

[1] https://www.crowdstrike.com/blog/who-is-ember-bear/

[2] https://www.microsoft.com/en-us/security/blog/2023/06/14/cadet-blizzard-emerges-as-a-novel-and-distinct-russian-threat-actor/

[3] https://attack.mitre.org/groups/G0034/

[4] https://www.welivesecurity.com/2023/02/24/year-wiper-attacks-ukraine/

[5] https://www.justice.gov/opa/pr/five-russian-gru-officers-and-one-civilian-charged-conspiring-hack-ukrainian-government

[6] https://thehackernews.com/2024/06/russian-national-indicted-for-cyber.html

[7] https://www.nioguard.com/2022/01/analysis-of-whispergate.html

[8] https://www.bellingcat.com/news/uk-and-europe/2021/04/26/how-gru-sabotage-and-assassination-operations-in-czechia-and-bulgaria-sought-to-undermine-ukraine/

[9] https://en.wikipedia.org/wiki/Poisoning_of_Sergei_and_Yulia_Skripal

Saturday, 1 October 2022

"Analysis of cyberweapons" course


I got requests from my colleagues from the US and EU universities to come up with the "Analysis of cyberweapons" course in English. In the first video, I start the series devoted to the analysis of the Russian cyberweapons used in the Russia-Ukraine war. 

The lessons will be published on my Patreon (https://www.patreon.com/alexanderadamov) and YouTube channel (https://www.youtube.com/c/MalwareResearchAcademy)

For Ukrainians:

Monday, 4 April 2022

Russian SaintBear Group Attacked Ukrainian Government Agencies Using GraphSteel & GrimPlant malware

 

Summary


  • Name: ‘Π—Π°Π±ΠΎΡ€Π³ΠΎΠ²Π°Π½Ρ–ΡΡ‚ΡŒ ΠΏΠΎ Π·Π°Ρ€ΠΏΠ»Π°Ρ‚Ρ–.xls’

  • Discovered in March 2022

  • Was used in attacks against Ukrainian government agencies

  • Used to download GraphSteel and GrimPlant (a.k.a. Elephant) malware

  • Spreads via phishing emails as ‘.xls’ file with malicious VisualBasic script

  • ‘.xls’ file contains the encoded payload

  • Extracted file has PE64 format and written in Golang, downloads one file from the remote server

  • The downloaded file is PE64 and written in Golang. It downloads GraphSteel and GrimPlant malware.

  • The attack has been attributed to UAC-0056 also known as SaintBear, UNC2589, and TA471 which is known to attack Ukraine and Georgia since 2021. 

Thursday, 17 March 2022

Analysis of CaddyWiper

 

Summary


  • Name: CaddyWiper

  • Discovered in March 2022

  • Was used in a targeted attack in Ukraine

  • Deployed via Microsoft Active Directory GPO

  • Corrupts files and disk partitions

  • PE32 sample written in C++

  • Compiled on the same day when it was deployed on targeted systems in Ukraine

by Denis Popov

Wednesday, 26 January 2022

Analysis of WhisperGate

 

Summary of the attack

  • Name: WhisperGate

  • Discovered in January 2022

  • Used in a targeted attack against the Ukrainian government websites on the 14th of January, 2022

  • Overwrites the contents of files with the fixed number of bytes

  • Rewrites MBR, corrupts victims’ files, downloads and drops its own files

  • Corrupted files have a random 4-byte extension

  • Comes with 2 stages, PE64 written in C++ and .NET application with fake digital signatures

  • The third stage is .NET DLL, which is downloaded at runtime


                                                                                                by Denis Popov and Alexander Adamov

Friday, 2 October 2020

Reinforcement Learning for Anti-Ransomware Testing



ML models have recommended themselves as a powerful tool for cyberdefense. AI/ML is heavily used in antiviruses (EDR), Next-Gen Firewalls, and SIEM (SOAR) solutions to solve the classification problem as well as to discover anomalous behavior that may indicate a presence of an attacker with the help of Supervised and Unsupervised Learning. Deep Learning helps to filter spam emails and mark fake news to protect users against disinformation [1].

Thursday, 26 March 2020

AI and Cybersecurity. Part 4 - Clustering URLs


In Part 3, we tried to apply the feature scaling and dimensionality reduction techniques to the dataset with phishing and benign URLs. As a result, we were able to clearly see the distribution of URLs between two classes based on four attributes: registrar, country, lifetime, and protocol.

But what if we don’t have labels (phishing and benign) for the Internet links in the beginning. Will ML still work to detect phishing attacks? In this case, we may come to unsupervised learning, in particular, clustering. Clustering enables grouping objects of unknown classes according to common features so that we do not need labeled data for a training set.

Wednesday, 18 March 2020

AI and Cybersecurity. Part 3 - Dimensionality Reduction and Feature Scaling

In the previous post, we created a binary classifier for detecting phishing URLs. Here, we're going to continue exploring the data with visualization techniques.

Monday, 16 March 2020

AI and Cybersecurity. Part 2 - Detecting Phishing URLs with ML

hack fraud card code computer credit crime cyber data hacker identity information internet password phishing pile privacy protection safety secure spy steal technology thief green cartoon text product line font illustration human behavior angle clip art graphics computer wallpaper

In Part 1, we already got acquainted with AI paradigms and the main ML approaches: supervised, unsupervised, and reinforcement learning. Even though the unsupervised learning approach looks more attractive as you do not need to pre-mark the data for training, supervised learning can be seen as a more precise instrument for detecting malicious objects such as phishing URLs once we have enough labeled data.

Saturday, 14 March 2020

AI and Cybersecurity. Part 1 - Intro

Image via www.vpnsrus.com
[Author: Alexander Adamov]

Foreword
I have spent almost all my professional life working in the antivirus industry detecting and analyzing malware. Around ten years ago, when the malware flow had increased so much that my colleagues and I did not have enough resources to analyze them all, we started thinking about automating our efforts. How to make a machine that autonomously detects and analyzes malware and phishing URLs day and night, writes and publishes reports? As a result, we managed to create a robot (what we call now 'malware sandbox') from scratch to automate most of the processes in the malware laboratory with the help of His Majesty Artificial Intelligence (AI). Since that, we accumulated a bunch of use cases for cyberattacks detection, malware analysis, and security testing with ML that can be useful for cybersecurity professionals that decided to leverage ML for cyberdefense. I'm going to share this knowledge in the series of blog posts that will eventually become a part of a new university course 'ML in Cybersecurity' that I plan to make open-source. I also welcome cybersecurity experts and data scientists to contribute and help universities adopting the course.

Monday, 9 December 2019

Analysis of Ryuk Ransomware

[Authors: Viktoria Taran, Alexander Adamov]

The Ryuk ransomware seen for the first time in August 2018 has been successfully used in targeted attacks encrypting data and asking for a ransom payment which differs from 10 BC to 50 BC. The recent attack was executed against DCH hospitals in Alabama on October 1st, 2019. As a result, DCH paid the ransom to recover the data stored on their servers. In this report, we analyze one of the recent versions of Ryuk ransomware discovering the installation process, networking details, and encryption model.

Sunday, 29 September 2019

GermanWiper: One More Wiper Pretending to Be Ransomware


[Authors: Viktoria Taran, Alexander Adamov]

GermanWiper was first seen on the BleepingComputer forum on July 30, 2019. After analysis, it turned out that the malware is rather a wiper than ransomware. Interestingly, GermanWiper managed to raise $9,000 almost reaching the result of $10,500 (4.13528947 BTC) earned by another wiper called NotPetya in June 2017. Let us take a close look at the ransomware to find out the installation process, communication details, and wiping details.

Tuesday, 27 August 2019

Anti-Cryptojacking Test - July 2019



Cryptojacking or malicious cryptomining is a new type of threat that can be described as the unsolicited use of a user’s computing device to mine cryptocurrency. There are two types of cryptojacking attack: general-purpose and targeted.

Saturday, 23 March 2019

Analysis of LockerGoga Ransomware


ÐšΓ°Γ‘€Γ‘‚Ð¸Γ½ΓΒΊΓ¸ Ð¿Γ¾ Ð·Γ°Γ¿Γ‘€Γ¾Γ‘Γ‘ƒ Norsk Hydro
Norsk Hydro back in 1905. 
Source: https://commons.wikimedia.org/wiki/File:Rjukan_fabrikker_-_Norsk_Hydro.jpg

This week BleepingComputer reported that LockerGoga ransomware was allegedly responsible for disrupting the Norsk Hydro's IT control system and forced the Norwegian industrial giant to switch to the manual operation mode. Later, according to Motherboard, this ransomware disrupted IT services of the two more US chemical companies Hexion and Momentive. Thus, it seems that the attackers behind LockerGoga target critical infrastructure and those mentioned above are not the only victims of the ransomware up to the moment. Further, we provide a detailed analysis of the ransomware encryption process.

Tuesday, 31 July 2018

VB2018: Artificial intelligence to assist with ransomware cryptanalysis



It's always very exciting for me to be able to attend and, moreover, speak at the Virus Bulletin Conference. Because, it is the oldest and the most respectful antivirus conference that has been running since 1991 where cybersecurity experts from academia and industry gather to share their ideas, research, and forecasts. You can meet the researches who helped to boost the antivirus industry decades ago and are now the core of the antivirus community.

This year in Montreal, we'll present an academic research conducted by my master student Kateryna Vitiuk under my supervision and devoted to Cryptanalysis of ransomware with the help of Artificial Intelligence.

When analyzing ransomware, we often see the hardcoded implementation of the AES, RC4, Salsa20 algorithms, for example in TeslaCrypt, Locky, GlobeImposter, MoneroPay ransomware. The ciphers' code can be poorly detected in the ransomware's memory dumps using the signature-based approach using Krypto ANALyzer (KANAL) for PEiD tool and publicly available Yara rules. Therefore, we assumed that it is possible to use the smart pattern matching method to find the known crypto primitives in the ransomware's disassembled code.

See also:
https://www.virusbulletin.com/conference/vb2018/abstracts/artificial-intelligence-assist-ransomware-cryptanalysis

Wednesday, 21 March 2018

Corporate Backup Solutions Self-Defense Test - March 2018


In the light of the growing number of ransomware attacks in which cryptolockers terminate database processes to unlock the database files for encryption (Cerber, GlobeImposter, Rapid, Serpent) and can encrypt local and network backups to demand a ransom (Rapid, Spora), we decided to test self-defense capabilities of the top backup solutions used in business environments available for trial.

The test aims at testing the sustainability of product’s processes and services against typical attacks to security software described below, as well as self-protection of local backup and product’s files. Ransomware can encrypt local backup files and configuration files that belong to a backup program thereby disabling the recovery of the files. Moreover, once access to agent’s or server’s processes is gained, an attacker can delete backup copies of the files not only locally, but also in the cloud on behalf of a backup solution.

See the full report by the link.

Sunday, 4 February 2018

Friday, 22 December 2017

VB2017 videos on attacks against Ukraine


Thanks to Virus Bulletin for giving a chance to talk about the most destructive attacks this year.
"(In)security is a global problem that affects every country in the world, but in recent years, none has been as badly hit as Ukraine.The most well known malware that affected the country is (Not)Petya, a ransomware/wiper threat that had global impact (it cost shipping firm Maersk alone $300m in lost revenues), but which hit Ukrainian businesses particularly hard. The malware spread through a compromised update pushed out by M.E.Doc's tax accounting software, which is popular in the country.
In a VB2017 presentation, NioGuard's Alexander Adamov, himself based in Ukraine, discussed how (Not)Petya and related attacks worked and what impact they had. We have now uploaded the video of his presentation to our YouTube channel."

Read more: