About Me

About Me

You might know me as RussianPanda. These days it’s PandaRE.

I’ve been in cybersecurity for over seven years. It started with an internship on the offensive side, sending phishing emails to employees and then helping train the ones who clicked. I still have the same motivation I had back then. Something happened, the evidence is right there, and nobody has worked out what it means yet.

I’m a jack of all trades on purpose. Reverse engineering, threat hunting, incident response, OSINT, CTI. I’ve spent real time in all of them and I’ve never thought of them as separate jobs. An obfuscated binary, a process spawning something sketchy, a domain registered three days before a campaign went loud, a handle someone reused on a forum years ago. That’s the same puzzle from different sides, and the people who solve cases fastest tend to be the ones who move between sides easily.

Why I built Malbear Labs

The useful stuff keeps ending up where nobody can get to it.

This industry learns a lot and then buries it. It goes into an internal wiki, or a private group chat. The person who actually needs it is working it out from scratch at 3 AM, and usually that’s a lone analyst, a one-person security team, or a student looking at their first real sample with no idea where to start.

That helps nobody. The people we’re up against share notes freely, so defenders should too.

Malbear Labs publishes what we find. How the malware works, how it came apart, which assumptions were wrong on the first pass and what fixed them.

If one write-up helps one person spot something a day sooner, it was worth writing.

The part I actually love

Puzzles.

Malware and interesting intrusions are the best kind, because somebody made it hard on purpose. They sat down and built the thing you’re looking at so it wouldn’t make sense. Every layer of packing, every junk instruction, every bit of misdirection is a choice, and choices tell you something about the person who made them. Sooner or later you learn something they didn’t mean to give away.

Working out what a sample is, or uncovering the intrusion chain, is still my favorite part of the job. That hasn’t changed in seven years.

If that sounds like your kind of thing, get in touch or find me on X.

→ Zero spam. Unsubscribe anytime.

--email

By subscribing you agree that we process your data to send you our newsletter. No third parties, no ads. Ever.