// about
Who I Am_
I'm Shmuel. Online I go by LikelyMalware, which started as a joke and stuck.
I've spent about a decade in cybersecurity and threat intelligence. I started with no knowledge at all, taught myself, and worked my way up. These days I lead a research team of nine people, which means I spend a lot less time hands-on than I would like and a lot more time in meetings than I would like.
Most of my career has been spent watching threat actors. Not just their malware, but them. How they organize, how they recruit, how they argue with each other, how they run what are essentially small businesses with terrible HR. I've monitored them, tracked them, and talked to some of them. It is the most interesting part of this job and it is what I write about most.
The other thing I am deep in right now is AI, specifically agentic systems. I build with them every day. I am also fairly skeptical of most of what gets sold as AI security, and I think both of those things can be true at once.

# status.json
{
"day_job": "leading nine",
"currently": [
"watching actors",
"building agents"
],
"open_to": [
"collaboration",
"arguments"
]
}// honesty
What I'm Not_
I am not a reverse engineer. I do malware analysis when something catches my interest, mostly for fun, and I enjoy the technical side. But I am not going to pretend to a skill I do not have, and if you want deep RE there are people far better than me doing it.
I also do not write about regulation or compliance. I do not know enough about it to have an opinion worth reading.
This blog is where I put things I think are worth saying. If I do not have a real opinion on something, I would rather post nothing.
// what i actually do
Areas of Focus_
Threat Intelligence
- ▸actor tracking
- ▸humint
- ▸underground forums
- ▸osint
Security Research
- ▸botnet research
- ▸protocol research
- ▸signature development
- ▸malware analysis
AI & Agents
- ▸agentic workflows
- ▸agent memory
- ▸llm security
- ▸prompt injection
Leading
- ▸a team of nine
- ▸mentoring
- ▸hiring
- ▸too many meetings
Want to talk threat actors or agents?
Reach out on X