
Quentin Bourgue
Senior Threat Researcher
Quentin Bourgue is a senior threat researcher in Sekoia's Threat Detection & Research (TDR) team, leading investigations into financially motivated threats and the associated cybercrime ecosystem. His research covers malware distribution campaigns, prominent Malware-as-a-Service offerings, Phishing-as-a-Service platforms, and, more broadly, tracking adversary infrastructure.
Articles by Quentin Bourgue

Don’t eat the ChocoPoCs! How vulnerability researchers were repeatedly targeted by trojanised exploits
This article details a campaign targeting vulnerability researchers with "ChocoPoC" malware embedded inside trojanised Python dependencies. Exploiting the pressure to quickly test new vulnerabilities, threat actors distribute a persistent Remote Access Trojan (RAT) that exfiltrates data and harvests credentials from compromised developer environments.

Unveiling ErrTraffic: inside a growing ClickFix malware distribution framework
This report details the ErrTraffic threat and its associated ecosystem, highlighting three specific campaigns and their operators' arsenal.

EvilTokens: an AI-augmented Phishing-as-a-Service for automating BEC fraud - Part 2
Explore how EvilTokens uses AI-driven features to automate and scale BEC workflows. Uncover the PhaaS operations on Telegram.

New widespread EvilTokens kit: device code phishing as-a-service - Part 1
Uncover the new sophisticated EvilTokens device code phishing as-a-service, with AI-augmented features facilitating BEC fraud.

Meet IClickFix: a widespread WordPress-targeting framework using the ClickFix tactic
Uncover IClickFix: a malicious framework exploiting the ClickFix tactic in widespread malware campaigns to deliver NetSupport RAT.
Phishing Campaigns "I Paid Twice" Targeting Booking.com Hotels and Customers
Sekoia.io exposes a Booking.com phishing campaign targeting hotels and customers using ClickFix and PureRAT malware.

ClearFake’s New Widespread Variant: Increased Web3 Exploitation for Malware Delivery
ClearFake's new variant abuses the Binance Smart Chain and fake CAPTCHAs to deliver malware. A technical analysis of its Web3 evasion and ClickFix infection chain.

Targeted supply chain attack against Chrome browser extensions
On 26 December 2024, the data security company Cyberhaven informed its users about a compromise of their Chrome browser extension. The attacker exploited the extension developer's permissions, which had been previously gained through a targeted phishing campaign.

Sneaky 2FA: exposing a new AiTM Phishing-as-a-Service
In this blog post, learn about Sneaky 2FA, a new Adversary-in-the-Middle (AiTM) phishing kit targeting Microsoft 365 accounts.

ClickFix tactic: The Phantom Meet
This blog post provides a chronological overview of the observed ClickFix campaigns. We further share technical details about a ClickFix cluster that uses fake Google Meet video conference pages to distribute infostealers.

Exposing FakeBat loader: distribution methods and adversary infrastructure
During the first semester of 2024, FakeBat (aka EugenLoader, PaykLoader) was one of the most widespread loaders using the drive-by download technique.

PikaBot: a Guide to its Deep Secrets and Operations
This blog post provides an in-depth analysis of PikaBot, focusing on its anti-analysis techniques implemented in the different malware stages.

Scattered Spider (aka UNC3944, Octo Tempest, Muddled Libra) Laying New Eggs
This report provides an overview of the Scattered Spider evolution, its modus operandi and the toolset leveraged over the past years. Additionally, it delves into the Scattered Spider TTPs, as well as the latest ongoing campaigns.

Adversary infrastructures tracked in 2023
Sekoia.io C2 Trackers identified more than 85,000 IP addresses used as C2 servers in 2023, an increase of more than 30% compared to 2022.

ClearFake: A newcomer to the "fake updates" threat landscape
ClearFake is a new malicious JavaScript framework deployed on compromised websites to deliver further malware using the drive-by download technique.

CustomerLoader: A new malware distributing a wide variety of payloads
This blog post aims at presenting a technical analysis of CustomerLoader focusing on the decryption of the next-stage payloads, an overview of more than 30 known and distributed malware families, and details on three infection chains observed distrib

Overview of the Russian-speaking infostealer ecosystem: The logs
This blog post aims at presenting the life cycle of logs, the cybercrime marketplaces dedicated to logs and the noticeable schemes recently used by threat actors to exploit the stolen data.

Overview of the Russian-speaking infostealer ecosystem: The distribution
This blog post aims at presenting the main techniques, tools and social engineering schemes used by the cybercriminals from the Russian-speaking infostealer ecosystem and observed by Sekoia analysts in the past year.
Stealc: A copycat of Vidar and Raccoon infostealers gaining in popularity - Part 2
This blog post is a technical analysis of Stealc infostealer, detailing different characteristics of the malware, including anti analysis, strings de-obfuscation and C2 communication techniques.

Stealc: a copycat of Vidar and Raccoon infostealers gaining in popularity - Part 1
This blogpost aims at presenting the activities of the Stealc’s alleged developer, a technical analysis of the malware and its C2 communications, and how to track it.

Unveiling of a large resilient infrastructure distributing information stealers
This blogpost aims at presenting the current infection chain, payloads and the whole infrastructure used to distribute infostealers

PrivateLoader: The loader of the prevalent ruzki PPI service
Sekoia analysts tracked PrivateLoader’s network infrastructure for several months and recently conducted an in-depth analysis of the malware. In parallel, we also monitored activities related to the ruzki PPI malware service.

Traffers: A deep dive into the information stealer ecosystem
Traffers are responsible for redirecting user traffic to malicious content (malware, fraud, phishing, scam) exploited by other threat actors.

Ongoing Roaming Mantis smishing campaign targeting France
MoqHao (aka Wroba) is an Android Remote Access Trojan (RAT) with information-stealing and backdoor capabilities that likely spreads via SMS.

Raccoon Stealer v2 - Part 2: In-depth analysis
This blog post is a technical analysis of the new Raccoon Stealer 2.0 stand-alone version. Authors have announced that the malware is also available in a DLL format or could be embedded in other PE.

Raccoon Stealer v2 - Part 1: The return of the dead
On June 10, 2022, Sekoia analysts stumbled upon active servers hosting a web page named “Raccoon Stealer 2.0”. Discover their research.

BumbleBee: A new trendy loader for Initial Access Brokers
BumbleBee is a new malicious loader that is being used by several IABs to gain an initial foothold within victims' networks.

EternityTeam: a new prominent threat group on underground forums
During our monitoring of Dark Web cybercrime forums, we came across EternityTeam: here is what we found on this new active & organized threat

An insider insight into Conti operations – Part Two
This is the second part of our blog post about Conti, here we'll see how to detect Conti Operations techniques and much more.





