Nathan Collier Malware Analysis
Grow Your Vision
Welcome visitors to your site with a short, engaging introduction.
Double click to edit and add your own text.


Nathan Collier
Malware Analyst
EXPERIENCE
Malwarebytes
Senior Malware Intelligence Analyst
June 2014 - February 2024
​
Webroot
Senior Threat Research Analyst
October 2009 - June 2014
​
-
Conducting research to discover spyware/malware on PC and Android devices
-
Classifying PC and Android spyware/malware based on unique behavior
-
Creating signatures in order to detect and remove spyware/malware from infected PC and Android devices
-
Identifying new distribution methods and techniques for removal
-
Analyzing information and developing methods of detection and removal of spyware/malware
-
Reverse engineering spyware/malware in order to create signatures off of unique sections of malicious code
-
Writing security blog posts on the company website, Webroot Threat Blog
-
Administrator for the Threat Research domain
-
Extensive testing of new security software
-
Querying SQL database to data mine for Android threats
-
Automating various tasks using scripting
-
Ensuring any issues our customers may have are resolved in a timely manner
-
Managing multiple projects simultaneously while quickly gaining knowledge regarding new concepts and technologies
Modern Woodmen of America
Network Analyst
October 2006 - October 2009
​
-
Deploying, configuring, managing, maintaining, and troubleshooting a network with over fifty servers (application, domain controllers, file, mail, web, etc), two sites, and a replicated SAN system
-
Administrating a domain of over five hundred users which includes creating/removing users and groups, assigning permissions, assigning disk quota limits, etc
-
Using scripting to automate various tasks such as file transfers, generating reports, administrative tasks, etc
-
Maintaining the integrity of the company’s email/web system through administration of email/web filters
-
Maintaining the integrity of company’s data through administration of disk and tape based backups/restores
-
Upgrading workstations/servers operating systems, software, etc
-
Administration of the company’s firewall and access control list
-
Research and Implementation of fixes for security vulnerabilities
-
Deploying, managing, and troubleshooting company’s file transfers
-
Creating websites for intranet users to view microfiche images
-
Research, development, and purchasing of required software and hardware
-
Proficiently troubleshooting anything IT related
-
Leading expert in classification of Android malware using complex, high quality signatures to classify large samplesets
-
Creating the highest detections per signature seen on Android customers devices
-
-
Working diligently with customers to resolve tough issues
-
Beyond being main contact for forum support for all things Android, I also assist with arduous cases submitted via our support staff
-
-
Creator and maintainer of the Mobile Malware Intel System
-
The Mobile Malware Intel System is the genius behind our high efficiency of classifying malware with a limited number of staff members
-
This system contains millions of Android malware samples
-
-
An Android malware classification system made by a researcher, for researchers
-
Over half million signatures created in the system to combat Android malware
-
-
It is a complex system involving Amazon EC2 running Ubuntu server, Amazon RDS running MySQL, and python scripts
-
Being the single contact of the development on the Mobile Malware Intel System creates a space of high agility among the Android protection team
-
Key components
-
Multi-threaded APK Processors
-
Processes thousands of incoming APKs per day
-
Uses androguard and many other tools to analyze Android malware
-
Android malware samples are broken down into data points and sent to Mobile Malware Intel database
-
-
APK Classifiers
-
Classifies malware in our Mobile Malware Intel database to sort what needs to be worked on or not
-
-
Insert Signatures
-
Inserts signatures into our Mobile Malware Intel database to classify malware
-
-
Update Signatures
-
Updates signatures when modifications is required
-
-
Create Sig File
-
Creates signature files to be download on customer devices
-
Performs FP check before creation of signature files
-
Signature files are packaged and turned into Malware Database to be released onto Malwarebytes for Android clients
-
-
Auto Detector
-
Automatically creates signatures to classify malware, leaving only the toughest malware samples to us experts
-
-
Various other scripts to do a multitude of things, and always scripting to be on the leading edge
-
-
-
Contributor to Malwarebytes Labs generating some of the highest viewed blogs on the site
-
In addition, working with PR on requests from leading news outlets
-
Contributor to yearly State of Malware report
-
-
Going beyond core responsibilities
-
Performing QA work to resolve client issues
-
Detailed steps to reproduce issues
-
-
Scripting using Windows Batch and WinSCP to assist automation of Malware Database releases onto Malwarebytes for Android clients
-
Use of Jenkins to automate the process
-
-
Training and mentoring the best Android malware researchers in the industry
-
Creating easy to understand training documentation including efficient workflow chart
-
-
Documenting incident response procedures such as a simplified method for anyone to follow on how to resolve a Android False Positive (FP)
-
-
Forefront on the battle against pre-installed malware
-
Creation of tutorial on how to remove pre-installed malware
-
Blowing the whistle on United States government-funded phones that come pre-installed with malware
-
Working internally on how to address pre-installed malware
-
-
Founding member of the Coalition Against Stalkerware
-
Fiercely fighting against stalkerware on Android devices
-
Adding over hundred detections created that no other vendors detected
-
EDUCATION
2006
Bachelor of Science in Computer Science
University of Illinois at Springfield
-
Overall GPA: 3.85/4.0
-
Graduated with Cum Laude honors
TECHNICAL SKILLS

Programming & Scripting Languages
-
Proficient in python
-
Experienced with C++, HTML, Java, VBScript, PowerShell, Windows Batch, and Linux Shell
-
Familiar with C, CSS, Perl, XML, JScript, JavaScript, etc
Databases
-
Proficient in MySQL Workbench
-
Proficient in MySQL database design
-
Expert in MySQL queries
Cloud/Virtual technologies
-
Proficient in creation/administration of Amazon Web Services (AWS) including EC2, RDS, and S3
-
Proficient in virtual environments including VMWARE, VirtualBox, and GenyMotion Android Emulators
-
Working knowledge of distributions FlareVM and REMnux
-
Operating Systems
-
Deep knowledge of Windows
-
Registry files, configuration files, file system, etc
-
-
Deep knowledge of Linux
-
Linux/Unix file system, sudo/root level administration, server maintenance, etc
-
-
Deep knowledge of Android
-
Analyzing Manifest files to find relevant information such as receivers, services, and activities
-
Deep analytical understanding of APKs
-
Networking/Protocols
-
Strong understanding and advanced troubleshooting skills in TCP/IP, DNS, DHCP, FTP, HTTP, SMTP, DFS, FRS, Firewalls, and VPN
Encryption
-
Strong knowledge of PGP
-
Strong knowledge of creation and implementing keypairs
SSH/Proxy/Tunneling
-
Strong knowledge of setting up PuTTY connections
-
Strong knowledge of SSH command line
-
Strong knowledge of implementing Bastion servers to tunnel connections
-
Strong knowledge of FTP servers WinSCP, Filezilla, and more
Regular Expressions
-
High level understanding of Regex
Text Editors
-
High level expertise using Notepad++ to create an efficient workflow
Cybersecurity/Monitoring/Analyzing Tools
-
Virtual Environments
-
Windows with FlareVM installed
-
Linux with REMux
-
-
Windows malware analysis
-
In depth knowledge of dynamic analysis tools Process Explorer (ProcExp), Process Monitor (Procmon), and others used to monitor the behavior of spyware/malware
-
Working knowledge of static analysis tools IDA Pro, Ghidra, Olly Debug, x64dbg, FLOSS, HxD, CFF Explorer, PEiD, PETools, PEview, and others used to analyze PE files for the creation of signatures to detect spyware/malware
-
Working knowledge of the use of Rootkit Revealer, Gmer, and Rootkit Unhooker used to unhook rootkits
-
-
Android malware analysis
-
Expertise with analysis tools Apktool, dex2jar, JD-GUI, androguard, Android Device Monitor, Logcat, and many more
-
-
Network analysis
-
Expertise with analysis tools Fiddler, Wireshark, Network Miner, tcpdump, FakeNet, iNetSim, and many more
-
​Working knowledge of Intrusion Detection Systems (IDS) and sniffers such as Snort
-
-
​Threat Hunting
-
Expertise threat hunting malware on VirusTotal, MalwareBazaar, Hybrid Analysis, and other repositories
-