KAIZEN
$ ls ~/research

Research

First-party threat research, published in full. Each paper is an investigation I ran myself, from a single artifact to the infrastructure behind it. Sources, indicators and methods are included so the work can be checked, and where something is undetermined it says so.

Command and Control is a multi-part series on the infrastructure layer: who supplies it, why it survives takedown, and what that means for the small organisations sitting on top of it.

Essay

Immutable Both Ways

Aug 8, 2026 · #threat-intelligence #etherhiding #clickfix

A ClickFix popup on a neighbourhood bar's website turned out to be an EtherHiding loader that asks a smart contract where to send its victims. Reading is free and leaves no trace; writing is a signed, timestamped, public transaction — so the contract holds every address change the operator ever made and nothing else. One hundred and forty four changes across five months: a contract deployed broken and replaced in 114 seconds, a data-format change dated to a twelve-minute window, and the afternoon in June he handed domain naming over to a generator. Includes three negative results and the one server header that defeats the delivery.

Essay

Nobody Owns the Rails

Jul 7, 2026 · #threat-intelligence #abuse-economics

A first-person threat-research investigation that begins with a single 'Claude, never banned' ad and follows it down through the residential-proxy botnet economy, the commodity-malware market, and the AI-distillation war — to one organizing principle: nobody owns this infrastructure. It is a commons that criminals, corporations, and states all draw from, which is why nothing kills it.