I'm Malware Researcher focused on reverse engineering, malware evolution, and detection-oriented research.
My work centers on understanding how real-world malware is designed, how it evolves over time, and why specific implementation choices are made. Through reverse engineering and comparative analysis, I study malware behavior, evasion techniques, and their implications for detection, threat intelligence, and defensive engineering.
- Reverse engineering of Windows malware (ransomware, RATs, droppers, and related malware families)
- Comparative analysis of malware evolution, implementation choices, and behavioral patterns
- Static and dynamic malware analysis
- Unpacking, deobfuscation, and anti-analysis research
- Detection engineering with YARA, Sigma, IOC extraction, and MITRE ATT&CK mapping
- Research tooling and workflow automation in C/C++ and Python
- Currently expanding into Android malware research
Longitudinal technical research covering BlackCat ransomware (2021β2023).
The project analyzes behavioral evolution, cryptographic implementation, operational changes, and implementation differences across multiple Windows, Linux, and PowerShell samples, together with their implications for detection and defensive engineering.
β https://github.com/Arrbat/MALWARE_ANALYSIS/tree/main/BLACKCAT
Technical reports documenting reverse engineering, behavioral analysis, IOC extraction, ATT&CK mapping, and detection-oriented findings for real-world malware families including Agent Tesla, Remcos RAT, and others.
β https://github.com/Arrbat/MALWARE_ANALYSIS
Research-oriented PE packer written in C to study modern packing techniques, anti-analysis methods, and reverse engineering implications.
Implements ChaCha20-Poly1305, HKDF, anti-debugging, process hollowing, and related techniques.
β https://github.com/Arrbat/Veil-Forge
Utilities and automation scripts supporting malware triage, deobfuscation, indicator extraction, and analysis workflows.
Reverse Engineering
- Binary Ninja
- Ghidra
- x64dbg / x32dbg
- x86 / x64 Assembly
Programming
- C / C++
- Python
Malware Analysis
- Static & Dynamic Analysis
- Windows Internals
- Unpacking & Deobfuscation
Detection Engineering
- YARA
- Sigma
- IOC Extraction
- MITRE ATT&CK Mapping
Other
- Applied cryptography
- Ukrainian β Native
- Russian β Native
- English β B2
- Polish β B1
- Discord: arrbat
- Email: gvl7kdlcc@mozmail.com


