/LikelyMalware

Have You Tried Turning It Off And On Again?

I stopped writing here for a while. Here is the honest reason why, and what I am going to do about it.

August 20, 2026 5 min read

Hello there cyber fanatics!

I used to write here fairly regularly. Then I stopped, and if you had asked me why at the time I would have said I was busy. That was true, but it was not the real reason.

The real reason is that I got in my own head about it.

Every time I saw something worth writing about, one of two things happened. Either I thought "someone already covered this," or I thought "who am I to have the definitive take here." Both of those sound like good reasons to stay quiet. Neither of them actually is.

So I am turning it off and on again.

The thing I got wrong

"Someone already covered this" assumes the value is in the fact. It usually is not. The fact is on twelve news sites by lunchtime and none of those write-ups tell you what it means.

I have spent about a decade watching threat actors. Not just their malware, but them. How they organize, how they recruit, how they argue with each other in forum threads, how they run what are basically small businesses with genuinely terrible HR. I have monitored them, tracked them, and talked to a few of them.

That gives me a read on a story that a news write-up does not have. Not a better fact. A different angle on the same fact. Took me an embarrassingly long time to work out that this is the entire point.

Threat actors, mostly

This is the part I actually enjoy, so it is going to be most of what shows up here.

The thing I keep coming back to is that these groups are organizations. They have founders and middle managers and documentation policies and people who are quietly bad at their jobs. When the Conti chats leaked in 2022 and we all spent weeks reading them, the most interesting thing in there was not the malware. It was watching a crime syndicate run performance reviews.

I will write about groups, how they operate, what their behavior tells you, and where I think they are going. Full research write-ups on specific actors will usually go up on the Check Point blog, because that is where the traffic is and I would rather you actually read it. I will link them here.

AI, honestly

I build with agentic systems every day. I am also deeply skeptical of most of what gets sold as AI security. Both of those are true at the same time and I do not think that is a contradiction.

What I find genuinely interesting right now is the boring stuff nobody is writing about. How do you know a change to a prompt or a workflow actually made things better at scale? Almost nobody has a real answer and almost nobody is asking the question. Everyone became a builder overnight without learning the architecture underneath.

What I find less interesting is the tenth agentic scanner this quarter that is the same model with the same prompts in a different logo.

The stuff that keeps happening

Here is the thesis I keep returning to, so you may as well hear it now.

The circle does not break. New technology, new methods, same balance between attackers and defenders. Nobody wins. Anyone promising you total protection, or telling you AI has fundamentally changed the game, is selling something.

I have been around long enough to watch at least two full turns of this. A technique gets rediscovered, renamed, and sold back to us as new. Half of what I write is going to be pointing at something from 2008 and saying look, we have done this before, here is what happened last time.

Tutorials, when I feel like it

I said something once about this blog being observations rather than tutorials. That was not really me, and it disowned the best thing I have written.

The anti-debugging post I did a while back was a straight tutorial. It was also the most likeable thing on this site, because writing it forced me to actually understand the thing properly. Teaching is how I learn. So yes, tutorials, whenever something catches my interest.

What I am not going to do

I am not a reverse engineer. I do malware analysis when something grabs me, mostly for fun, and I like the technical side of it. But I am not going to pretend to a skill I do not have. If you want deep RE there are people much better than me at it.

I am not going to write about regulation or compliance either. I do not know enough to have an opinion worth your time.

And I am not going to post filler. If I do not have a real read on something, you will not hear from me that week. I would rather this place be quiet than full of things that could have been written by anyone, or by nothing.

So

New posts when I have something. Some of it technical, some of it me arguing with the industry, some of it looking backwards at things we should have learned already.

If you have been here before, thanks for sticking around. If you are new, welcome.

Have fun out there, and good luck!