whoami

Krasimir Konov

Security Engineer · Malware Analyst · Threat Research

Security engineer with 16 years in web security, including 9+ years at GoDaddy/Sucuri specializing in malware analysis and threat research. I reverse-engineer obfuscated PHP and JavaScript, build automated detection signatures (YARA, regex) deployed at scale across millions of websites, and publish original threat research — including work referenced in a peer-reviewed 2025 ACM SIGSAC (CCS) conference paper.

Security Engineer III · GoDaddy / Sucuri — Remote · Sofia, Bulgaria

Krasimir Konov

16

years in web security

9+

years at GoDaddy / Sucuri

1

CCS 2025 paper citation

25+

published threat research pieces

Featured

Peer-reviewed citation

My 2022 write-up Massive WordPress JavaScript Injection Campaign Redirects to Ads was cited as a reference in a peer-reviewed paper at the 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS):

What Gets Measured Gets Managed: Mitigating Supply Chain Attacks with a Link Integrity Management System” →

What I do

Core skills

Elsewhere

Currently

Day job

Reverse-engineering malware and shipping detection signatures at GoDaddy / Sucuri.

Automating

Building CI/CD-style pipelines — GitHub workflows that trigger AWS Lambda functions to QA new signatures in the cloud before they ship to analysts and deploy across our scanner network.

Teaching machines

Training AI agents to draft signatures for straightforward malware, so analysts can spend more time on novel, complex threats.

Maintaining

Fixing and modernizing internal tooling that had fallen out of date, so the team can move faster.

Writing

Publishing threat research on the Sucuri and GoDaddy blogs.

Building

Personal tooling and research on GitHub — more landing soon.