Alexandre Côté Cyr

Alexandre Côté Cyr

Malware Researcher


Education:
B.Sc.A in Computer Science and Software Engineering from the Université du Québec à Montréal.

What malware do you hate the most?
Commercial spyware. Especially when used against journalists, civil society and vulnerable people.

Golden rule for cyberspace?
Cyberspace isn’t a separate realm anymore, it’s woven into the “real” world in ways we often don’t think about or notice.

Favorite computer game/activity?
CTFs and CRPGs.


7 articles by Alexandre Côté Cyr

Beware the SparroWock: The backdoor that bites, the commands that catch

Beware the SparroWock: The backdoor that bites, the commands that catch

Beware the SparroWock: The backdoor that bites, the commands that catch

ESET researchers document SparroWocky, the new flagship backdoor of the FamousSparrow APT group

Alexandre Côté Cyr and Romain Dumont • 17 Sep 2026 • 17 min. read


You will always remember this as the day you finally caught FamousSparrow

You will always remember this as the day you finally caught FamousSparrow

You will always remember this as the day you finally caught FamousSparrow

ESET researchers uncover the toolset used by the FamousSparrow APT group, including two undocumented versions of the group’s signature backdoor, SparrowDoor

Alexandre Côté Cyr • 26 Mar 2025 • 24 min. read


Life on a crooked RedLine: Analyzing the infamous infostealer’s backend

Life on a crooked RedLine: Analyzing the infamous infostealer’s backend

Life on a crooked RedLine: Analyzing the infamous infostealer’s backend

Following the takedown of RedLine Stealer by international authorities, ESET researchers are publicly releasing their research into the infostealer’s backend modules

Alexandre Côté Cyr • 08 Nov 2024 • 20 min. read


MQsTTang: Mustang Panda’s latest backdoor treads new ground with Qt and MQTT

MQsTTang: Mustang Panda’s latest backdoor treads new ground with Qt and MQTT

MQsTTang: Mustang Panda’s latest backdoor treads new ground with Qt and MQTT

ESET researchers tease apart MQsTTang, a new backdoor used by Mustang Panda, which communicates via the MQTT protocol

Alexandre Côté Cyr • 02 Mar 2023 • 9 min. read


A lookback under the TA410 umbrella: Its cyberespionage TTPs and activity

A lookback under the TA410 umbrella: Its cyberespionage TTPs and activity

A lookback under the TA410 umbrella: Its cyberespionage TTPs and activity

ESET researchers reveal a detailed profile of TA410: we believe this cyberespionage umbrella group consists of three different teams using different toolsets, including a new version of the FlowCloud espionage backdoor discovered by ESET.

Alexandre Côté Cyr and Matthieu Faou • 27 Apr 2022 • 33 min. read


Mustang Panda’s Hodur: Old tricks, new Korplug variant

Mustang Panda’s Hodur: Old tricks, new Korplug variant

Mustang Panda’s Hodur: Old tricks, new Korplug variant

ESET researchers have discovered Hodur, a previously undocumented Korplug variant spread by Mustang Panda, that uses phishing lures referencing current events in Europe, including the invasion of Ukraine

Alexandre Côté Cyr • 23 Mar 2022 • 15 min. read


KryptoCibule: The multitasking multicurrency cryptostealer

KryptoCibule: The multitasking multicurrency cryptostealer

KryptoCibule: The multitasking multicurrency cryptostealer

ESET researchers analyze a previously undocumented trojan that is spread via malicious torrents and uses multiple tricks to squeeze cryptocoins from its victims while staying under the radar

Matthieu Faou and Alexandre Côté Cyr • 02 Sep 2020 • 11 min. read