Malicious Infrastructure Hunting
Phishing kits, cloned storefronts, fake applications and the hosting behind them. Detection, evidence collection, and reporting into the corpora other defenders rely on.
[ INDEPENDENT SECURITY RESEARCH · SINCE 2012 ]
I find malicious sites, phishing kits and abusive infrastructure, then report them. No company behind me. The work runs through the communities that keep the open web's abuse data honest.
01
It started in 2012 out of curiosity. One question about how a system really worked, followed further than it needed to be. That never stopped, and somewhere along the way it became the work itself.
I am not attached to any company. What I do runs through communities. I contribute to PhishTank, the phishing corpus operated by Cisco Talos, and I flag suspicious URLs on urlscan.io as they cross my path. When I find a vulnerability in a public institution's systems, I report it to that institution directly. Whatever malicious thing I come across, a site, an application, an infrastructure pattern, it goes to whoever can act on it.
Hardware sits underneath all of it. Between 2016 and 2023 I mined Ethereum, Bitcoin and Ravencoin on physical GPU rigs. That taught me more about firmware, power and thermals than any lab would have. The same bench now runs DGX Spark systems at home, where I build and fine-tune AI models locally instead of renting someone else's compute.
The thread I keep pulling on is cryptography under pressure. Post-quantum key exchange and signature schemes. How crypto-agility holds up in systems that were never designed for it. What quantum-resistant assumptions do to the layers above them: TLS termination, DDoS mitigation at the edge, chain-level signing. I read the standards, run the implementations and take notes. The migration will be someone's problem long before it is anyone's product.
02
Six areas, one thread running through them: understanding the infrastructure before the adversary does.
Phishing kits, cloned storefronts, fake applications and the hosting behind them. Detection, evidence collection, and reporting into the corpora other defenders rely on.
Submitting and flagging suspicious URLs on urlscan.io, then reading what comes back. The DOM, the redirect chain, the certificate and the hosting all point somewhere, and one artefact usually leads to the rest of the campaign.
Finding exposures in public sector systems and reporting them to the institution that owns them. Reproducible write-ups, nothing published before a fix, no leverage attached.
Seven years running physical GPU fleets across Ethereum, Bitcoin and Ravencoin. Pool credentials, firmware provenance, remote management, power and thermal limits, and the attack patterns that target hashrate rather than wallets.
Building on DGX Spark hardware at home. Local model development, fine-tuning and inference on machines I control, with the data never leaving the bench.
An ongoing research interest. ML-KEM and ML-DSA in practice, crypto-agility in systems never designed for it, and what post-quantum assumptions mean for TLS, edge DDoS mitigation and chain-level signing.
03
Volunteer work, mostly unsigned. This is where the hours actually go.
Submitting and verifying phishing URLs through PhishTank, the community corpus operated by Cisco Talos. Verified entries end up in blocklists, browsers and security products that will never learn my name, which is rather the point of it.
Suspicious links get submitted, scanned and flagged. The DOM, the redirect chain, the certificate and the hosting all leave a signature, and a flagged scan stays searchable for the next analyst who runs into the same infrastructure.
Exposures discovered in public institutions' systems go straight to the institution responsible, with reproduction steps and nothing published until it is fixed. Most of them carry no bounty and no credit. They get reported anyway.
04
Fourteen years, no employer in the middle of it.
Curiosity about how a system really worked, followed further than it needed to be. No plan attached and no job either, which turned out to be the useful part.
Physical rigs, run and maintained personally. Firmware, pool configuration, power draw and thermals stopped being topics and became a daily practice.
Unaffiliated. Malicious infrastructure reported through PhishTank and Cisco Talos, suspicious URLs flagged on urlscan.io, vulnerabilities disclosed directly to the public institutions that own them.
A home bench built around DGX Spark systems. Local model development, fine-tuning and inference on hardware I own, with nothing leaving the room.
05
Live from the sources I actually read. Threat reporting, digital assets and AI, pulled server side and cached at the edge.
06
A malicious site to report, a disclosure to coordinate, or a conversation about mining hardware, local AI and where cryptography goes next.
hello@okankilicer.com