I am Marcos Bajo h3xduck

Systems/Software security researcher

PhD Student at CISPA Helmholtz Center for Information Security

My Talks

My Work

Publications

Marcos Bajo, Christian Rossow
USENIX Security 2025

Honorable Mention (Top 6% paper)

Open Source Stuff I've made

A Linux eBPF rootkit with a backdoor, C2, library injection, execution hijacking, persistence and stealth capabilities.
The Coroutine Frame-Oriented Programming exploitation technique.
A LKM rootkit targeting 4.x and 5.x kernel versions which opens a backdoor that can spawn a reverse shell to a remote host, launch malware and more.
A C library for creating and using TCP/IP packets with raw network sockets.
A protocol reverse engineering framework with a custom Intel PIN multi-color tainting engine.
Android application for writing and saving encrypted notes.