
Quentin Bourgue
Senior Threat Researcher
Quentin Bourgue is a senior threat researcher in Sekoia's Threat Detection & Research (TDR) team, leading investigations into financially motivated threats and the associated cybercrime ecosystem. His research covers malware distribution campaigns, prominent Malware-as-a-Service offerings, Phishing-as-a-Service platforms, and, more broadly, tracking adversary infrastructure.
Articles by Quentin Bourgue

Exposing FakeBat loader: Distribution methods and adversary infrastructure
During the first semester of 2024, FakeBat (aka EugenLoader, PaykLoader) was one of the most widespread loaders using the drive-by download technique.

PikaBot: a Guide to its Deep Secrets and Operations
This blog post provides an in-depth analysis of PikaBot, focusing on its anti-analysis techniques implemented in the different malware stages.

Scattered Spider (aka UNC3944, Octo Tempest, Muddled Libra) Laying New Eggs
This report provides an overview of the Scattered Spider evolution, its modus operandi and the toolset leveraged over the past years. Additionally, it delves into the Scattered Spider TTPs, as well as the latest ongoing campaigns.

Adversary infrastructures tracked in 2023
Sekoia.io C2 Trackers identified more than 85,000 IP addresses used as C2 servers in 2023, an increase of more than 30% compared to 2022.

ClearFake: A newcomer to the "fake updates" threat landscape
ClearFake is a new malicious JavaScript framework deployed on compromised websites to deliver further malware using the drive-by download technique.

CustomerLoader: A new malware distributing a wide variety of payloads
This blog post aims at presenting a technical analysis of CustomerLoader focusing on the decryption of the next-stage payloads, an overview of more than 30 known and distributed malware families, and details on three infection chains observed distrib

Overview of the Russian-speaking infostealer ecosystem: The logs
This blog post aims at presenting the life cycle of logs, the cybercrime marketplaces dedicated to logs and the noticeable schemes recently used by threat actors to exploit the stolen data.

Overview of the Russian-speaking infostealer ecosystem: The distribution
This blog post aims at presenting the main techniques, tools and social engineering schemes used by the cybercriminals from the Russian-speaking infostealer ecosystem and observed by Sekoia analysts in the past year.
Stealc: A copycat of Vidar and Raccoon infostealers gaining in popularity - Part 2
This blog post is a technical analysis of Stealc infostealer, detailing different characteristics of the malware, including anti analysis, strings de-obfuscation and C2 communication techniques.

Stealc: a copycat of Vidar and Raccoon infostealers gaining in popularity - Part 1
This blogpost aims at presenting the activities of the Stealc’s alleged developer, a technical analysis of the malware and its C2 communications, and how to track it.

Unveiling of a large resilient infrastructure distributing information stealers
This blogpost aims at presenting the current infection chain, payloads and the whole infrastructure used to distribute infostealers
