RomHack Camp 2026

State Trojan: The Malware with a Warrant
2026-10-03 , STAGE 1 (Section 9)
Language: English

Your smartphone is not just a phone. It is your microphone, camera, archive, diary, GPS tracker, wallet, authenticator, and memory. In this talk, we will explore what happens when that device is turned into an informant during a legitimate criminal investigation through the use of lawful investigative malware, commonly known in Italy as a "captatore informatico".
We will start from the civic and legal tension: the need for effective investigations versus the privacy impact of compromising the most intimate device we own. Then we will move into the technical side, dissecting a real-world mobile implant to understand how it likely infected the device, what data it was able to collect, how it communicated, and what traces it left behind.
This is not an anti-law-enforcement talk. It is a hard look at the technical power of these tools, the risks created by their use, the vendors and supply chains behind them, and the practical signals defenders can monitor.

My journey started with technology. As a self-taught and curious teenager, I spent countless late-night hours exploring the emerging Internet, dismantling computers, and learning to program. That early hacker mindset shaped my long-term interest in complex systems, software, and security.

At a time when cybersecurity was not yet the established professional field it is today, I first applied this mindset in the life sciences, developing a background in molecular biology, marine biology, functional proteomics, and later bioinformatics. As a Senior Bioinformatician at the International Institute of Molecular and Cell Biology in Warsaw, I led the development of scientific tools and databases, while completing a PhD focused on computational biology and data analysis.

Over time, my focus moved decisively toward cybersecurity, where my experience in software engineering, data analysis, and complex-system modelling became directly applicable to digital defence. Today, I serve as CTO at AptGetDefence, leading Incident Response operations, R&D, and secure product development. I also advise organizations on NIS2 compliance, cyber resilience, and strategic security governance.

Recently, I was appointed Adjunct Professor at the University of Padua, where I teach “Internet Security”, combining academic rigor with real-world cybersecurity practice.

My work now focuses on threat mitigation, incident response, secure architectures, and regulatory readiness, helping organizations strengthen their security posture in an increasingly complex threat landscape.

My interest in technology started with a curiosity about how systems work and how they break. That curiosity eventually led me into infrastructure administration, where I spent several years managing enterprise environments and supporting critical systems.

Over time, I became increasingly interested in cybersecurity, particularly offensive security and adversary tradecraft. Today, I work as a penetration tester, conducting security assessments and red team engagements focused on identifying realistic attack paths and helping organizations strengthen their security posture.

My areas of interest include Active Directory security, Windows internals, command and control frameworks, and detection evasion. I hold the CRTO certification and continue to focus on developing practical offensive security skills through research, training, and real-world engagements.