Wojciech Bohatyrewicz
Wojciech Bohatyrewicz is a Threat Researcher at Atos Threat Research Center with 13 years of experience in security operations across SOC and CSIRT. In his current role, he analyzes advanced threat activity, malware campaigns, and real‑world incidents, translating OSINT and telemetry into actionable intelligence for detection and response teams.
He has extensive experience as both a CSIRT Lead and long‑standing CSIRT Engineer, leading and supporting complex, high‑impact security incidents across enterprise environments. He also supported security operations during the Paris 2024 Olympic Games as a CSIRT Duty Manager.
He has handled major security incidents including enterprise‑wide compromises, ransomware, and advanced malware campaigns, with deep expertise in digital forensics and post‑compromise analysis.
Session
In early 2026, Atos Threat Research Center (TRC) identified a sophisticated, high-resilience malicious campaign distributing malware EtherRAT. This operation specifically targets high-privilege IT professionals - enterprise administrators, DevOps engineers and security analysts - who hold broad credentials within corporate environments. The attackers leverage a combination of Search Engine Optimization (SEO) poisoning, impersonated administrative tools and a decentralized Command-and-Control (C2) mechanism utilizing the Ethereum blockchain to maintain persistence and bypass traditional security trust models.