About
Aleksandar Milenkoski is a Principal Threat Researcher at SentinelLABS. With expertise in malware research and focus on targeted attacks, he brings a blend of practical and deep insights to the forefront of cyber threat intelligence. Aleksandar has a PhD in system security and is the author of numerous reports on cyberespionage and high-impact cybercriminal operations, conference talks, and peer-reviewed research papers. From 2011 to 2014, he was a European Commission Marie Skłodowska-Curie Research Fellow. His research has won awards from SPEC, the Bavarian Foundation for Science, and the University of Würzburg.
Notable Work
Some of Aleksandar's contributions include uncovering the Sandman cyberespionage group, likely associated with suspected China-based groups, and Operation Tainted Love, attacks highly likely conducted by a Chinese cyberespionage actor related to Operation Soft Cell. Additionally, he made significant contributions to SentinelLabs' research on Metador, a never-before-seen advanced threat actor targeting entities in the Middle East and Africa.
In the Media
His research has been covered in leading media outlets, including Reuters, The Washington Post, Forbes, WIRED, Politico, The Record, and many other news platforms focusing on cybersecurity.
Collaborations
Aleksandar has actively collaborated with experts from the private and government sector, including:
- North Atlantic Treaty Organization (NATO)
- Microsoft Threat Intelligence Center (MSTIC)
- German Federal Office for Information Security (BSI)
- Netherlands Police
- Google Threat Intelligence (VirusTotal)
- PricewaterhouseCoopers (PwC)
- Recorded Future
Background
Aleksandar earned a PhD degree in cybersecurity in 2016 based on his research conducted at the Karlsruhe Institute of Technology (KIT) and University of Würzburg (Germany). From 2011 to 2014, he was a European Commission Marie Skłodowska-Curie Research Fellow.
He has served as an Adjunct Lecturer at the Baden-Württemberg Cooperative State University Mosbach and the University of Würzburg (Germany).
He has contributed as an expert to the NATO Defence Education Enhancement Programme (DEEP) initiative "Artificial Intelligence as a Tool for Military Power", supporting the development of education on artificial intelligence for military education institutions.
Awards
His academic research has been recognized with a research grant from the German Research Foundation (DFG), as well as awards from the Standard Performance Evaluation Corporation (USA), the Bavarian Foundation for Science, and the University of Würzburg.
Experience
Senior Threat And Malware Analyst
Show detailsHide details
- Established threat research methodology and reporting standards, and trained SOC analysts in cyber defence practice.
- Led the Cybereason Quarterly Threat Intelligence Report.
- Investigated and published on high-impact cyberespionage and cybercriminal operations, covering over 20 malware families, threat actors, and campaigns.
Senior Security Researcher and Reverse Engineer
Show detailsHide details
- Led long-term research projects for the German Federal Office for Information Security (BSI), Germany's national cybersecurity authority, including the SiSyPHuS Win10 study of Windows 10 security, alone spanning over 1,300 person-days.
- Analyzed 7 Windows user- and kernel-level security mechanisms, including Virtual Secure Mode and Windows Defender Application Guard, and authored over 10 public technical reports on the findings.
- Created a course on Windows internals, named "Insight into Windows Internals", and trained public and private sector professionals over 3 years. Founded the associated open-source project "Windows-Insight".
Computer Security Researcher
Show detailsHide details
- Awarded a PhD with honors, a grant for research in IT security by the German Research Foundation, and 5 recognitions for scientific achievements.
- Authored 14 peer-reviewed publications and 5 technical reports, published at top-tier conferences and journals, such as ACM Computing Surveys and International Symposium on Research in Attacks, Intrusions, and Defenses (RAID).
- Supervised 4 Bachelor and Master of Science theses and lectured undergraduate courses.
- Researched virtualization security, focusing on the top 3 market share hypervisors - Hyper-V, KVM, and Xen.
Visiting Computer Security Researcher
Show detailsHide details
- Researched virtualization security, focusing on the top 3 market share hypervisors - Hyper-V, KVM, and Xen.
Positions
Expert Contributor (Theme Co-Lead)
NATO Defence Education Enhancement Programme (DEEP) initiative "Artificial Intelligence as a Tool for Military Power"
Adjunct Lecturer
Adjunct Lecturer
Program Committee Member
Elected Chair
Elected Secretary
Research and Industry Paper Reviewer
- IEEE Transactions on Information Forensics & Security
- IEEE Transactions on Services Computing
- IEEE International Symposium on Software Reliability Engineering ISSRE 2015/2020
- ACM SIGMETRICS 2012
- IEEE Cloud Computing Magazine