
Quentin Bourgue
Senior Threat Researcher
Quentin Bourgue is a senior threat researcher in Sekoia's Threat Detection & Research (TDR) team, leading investigations into financially motivated threats and the associated cybercrime ecosystem. His research covers malware distribution campaigns, prominent Malware-as-a-Service offerings, Phishing-as-a-Service platforms, and, more broadly, tracking adversary infrastructure.
Articles by Quentin Bourgue

PrivateLoader: The loader of the prevalent ruzki PPI service
Sekoia analysts tracked PrivateLoader’s network infrastructure for several months and recently conducted an in-depth analysis of the malware. In parallel, we also monitored activities related to the ruzki PPI malware service.

Traffers: A deep dive into the information stealer ecosystem
Traffers are responsible for redirecting user traffic to malicious content (malware, fraud, phishing, scam) exploited by other threat actors.

Ongoing Roaming Mantis smishing campaign targeting France
MoqHao (aka Wroba) is an Android Remote Access Trojan (RAT) with information-stealing and backdoor capabilities that likely spreads via SMS.

Raccoon Stealer v2 - Part 2: In-depth analysis
This blog post is a technical analysis of the new Raccoon Stealer 2.0 stand-alone version. Authors have announced that the malware is also available in a DLL format or could be embedded in other PE.

Raccoon Stealer v2 - Part 1: The return of the dead
On June 10, 2022, Sekoia analysts stumbled upon active servers hosting a web page named “Raccoon Stealer 2.0”. Discover their research.

BumbleBee: A new trendy loader for Initial Access Brokers
BumbleBee is a new malicious loader that is being used by several IABs to gain an initial foothold within victims' networks.

EternityTeam: a new prominent threat group on underground forums
During our monitoring of Dark Web cybercrime forums, we came across EternityTeam: here is what we found on this new active & organized threat

An insider insight into Conti operations – Part Two
This is the second part of our blog post about Conti, here we'll see how to detect Conti Operations techniques and much more.



