Jean-Ian Boutin

Jean-Ian Boutin

Director of Threat Research


Education? B. Eng. Electical Engineering / M. Eng. Computer Engineering

Highlights of your career? My career highlight at ESET was able to present research I conducted at conferences such as Virus Bulletin and ZeroNights.

Position and history at ESET? I joined ESET in 2011. I am a malware researcher in the Security Intelligence program.

What malware do you hate the most? Win32/SpyEye. It was the first investigation I did when I joined ESET and, while it was a good learning experience, I still resent it ;)

Favorite activities? I love playing with my kids, cycling, jogging and playing the piano.

What is your golden rule for cyberspace? Be paranoid enough.

When did you get your first computer and what kind was it? My dad got me my first computer – a Commodore-64 – in 1988.

Favorite computer game/activity? My favorite computer game is the EA NHL series.


35 articles by Jean-Ian Boutin

Nymaim - obfuscation chronicles

Nymaim - obfuscation chronicles

Nymaim - obfuscation chronicles

We look at malware delivered by a campaign that has infected thousands of websites around the world - and the various control flow obfuscation techniques that make its analysis as interesting as it is challenging.

Jean-Ian Boutin • 26 Aug 2013 • 7 min. read


Operation Hangover: more links to the Oslo Freedom Forum incident

Operation Hangover: more links to the Oslo Freedom Forum incident

Operation Hangover: more links to the Oslo Freedom Forum incident

In our previous post on Operation Hangover, we revealed the existence of an attack group, apparently operating from within India, who were mainly targeting systems in Pakistan. In this post, we will analyze the Mac OS X samples that have been linked to this group and will provide new evidence that the Mac and Windows spywares are related.

Jean-Ian Boutin • 05 Jun 2013 • 2 min. read


Targeted information stealing attacks in South Asia use email, signed binaries

Targeted information stealing attacks in South Asia use email, signed binaries

Targeted information stealing attacks in South Asia use email, signed binaries

Detailed analysis of a targeted campaign that tries to steal sensitive information from different organizations throughout the world, but particularly in Pakistan.

Jean-Ian Boutin • 16 May 2013 • 9 min. read


Online PC Support scam: from cold calling to malware

Online PC Support scam: from cold calling to malware

Online PC Support scam: from cold calling to malware

Here's a brazen fake antivirus program that falsely declares you are infected, then locks your screen and asks you call a toll free number for Support, which then asks you to pay to remove the fake infection.

Jean-Ian Boutin • 18 Apr 2013 • 4 min. read


Code certificate laissez-faire leads to banking Trojans

Code certificate laissez-faire leads to banking Trojans

Code certificate laissez-faire leads to banking Trojans

Technical analysis of malware that abuses code signing certificates normally used to positively identify a software publisher and to guarantee code is unchanged.

Jean-Ian Boutin • 21 Feb 2013 • 6 min. read


Win32/Gataka – or should we say Zutick?

Win32/Gataka – or should we say Zutick?

Win32/Gataka – or should we say Zutick?

Jean-Ian Boutin • 30 Nov 2012 • 4 min. read


Win32/Gataka banking Trojan - Detailed analysis

Win32/Gataka banking Trojan - Detailed analysis

Win32/Gataka banking Trojan - Detailed analysis

Jean-Ian Boutin • 13 Aug 2012 • 8 min. read


Win32/Gataka: a banking Trojan ready to take off?

Win32/Gataka: a banking Trojan ready to take off?

Win32/Gataka: a banking Trojan ready to take off?

Jean-Ian Boutin • 28 Jun 2012 • 11 min. read