Thomas holds a PhD in computer science and worked until July 2022 as a Senior Cyber Security Analyst in the Cyber Threat Intelligence Chapter at Telekom Security GmbH. In his blogs he told techies and non-techies stories about his adventures in binary code wonderland.

Articles by Thomas Barabosch

Your choice

Smartphone showing a malware warning

Blog.Telekom

Flubot under the Microscope

Maybe Flubot is for SMS what Emotet was for email: a spam kingpin. How does it work and how do the operators prevent infiltration?

Fists of fire and water meet hard

Blog.Telekom

Let’s set ice on fire: Hunting and detecting IcedID infections

Emotet ist dead. IcedID belongs to the contenders to take its place. This is how you hunt for samples and detect local infections.

Insights into TA505’s ransomware operations.

Blog.Telekom

Inside of CL0P’s ransomware operation

Cybercrime actor TA505 started three waves of spam in 2020 to find new victims. Here are insights into their ransomware operations.

Smokeloader emerged from the Russian cybercrime underground in 2011 but is still alive.

Blog.Telekom

Smokeloader is still alive

One of the oldest malware families that is still in use today learned some new tricks: A special way to encrypt CC server URLs.

Researcher Thomas Barabosch will give recommendations to fight them and share ways to detect TA505 intrusions in your network.

Blog.Telekom

Eager Beaver: A Short Overview of the Restless Threat Actor TA505

Researcher Thomas Barabosch will give recommendations to fight them and share ways to detect TA505 intrusions in your network.

FAQ