bg
Point of view
11:38, 20 August 2026
views
13

Alexey Morozov: A Hacker Who Doesn’t Master Machine Learning Will Become an Outsider

Founder of G-HACK and GSPARK and a five-time winner of Russia’s national hacking competitions as a member of DreamTeam, Alexey Morozov spoke about what it takes to become a top-tier professional and how emerging technologies are reshaping the market.

Alexey Morozov is one of Russia’s best-known hackers, and he speaks completely openly about what he does. That’s because he hacks for one purpose only – to help companies discover their vulnerabilities and protect themselves against real attackers.

Over the course of his career, Alexey has taken on many different roles. He competed at PHDAYS Standoff, one of the largest hacking competitions in Russia and the CIS, winning five times as a member of DreamTeam. On multiple occasions, he found attack paths that no one before him had discovered. He shared that experience in talks delivered more than 100 times at scientific and industry conferences. Today, he is a successful entrepreneur and the founder of two companies – G-HACK and GSPARK.

In an in-depth interview with IT Russia, Alexey discussed how his hacking career began, what it takes to become a top-tier professional, and why mastering the art of machine learning is becoming essential.

Youthful Exuberance Started My Career

– How does someone actually become a professional hacker? Was there a moment when you realized, “This is something I want to pursue seriously”?

– I’ve been hacking – or, as we call it in the professional community, analyzing system security – for 15 years now. My team and I go into a company, hack it, and then explain to the company’s employees how we did it and what vulnerabilities we found. There are “white hat” hackers and “black hat” hackers. I’m on the side of the good guys, which is why I can talk about all of this so openly now.

As for how I got into the profession, that’s actually one hell of a story, and I love telling it. When I was a teenager, I used to rap. Around that time, online rap battles were becoming popular. You’d record a track and submit it to a website. The judges would score it and decide whether you advanced to the next round.

Then, in one of those battles, I thought the judges had screwed me over. Youthful exuberance got the better of me, so I went online and searched for how to hack a website. I ended up on a forum, where some hackers got in touch with me, explained how things worked, walked me through it – and that became my first hack. That’s how I became a hacker.

– Is it really that simple? I’ve heard the hacker community is very closed.

– Not really. These days, it’s fairly open. Anyone who wants to can become a hacker.

No Accidental Wins

– You became champion five times at the country’s largest hacking competition as a member of DreamTeam. What separates a team that wins once from one that can keep winning again and again?

– First and foremost, it’s about having a systematic approach. If a team wins once by accident, you could say they just got lucky. But PHDAYS Standoff is the largest hacking competition in Russia and the CIS, and it’s virtually impossible to win there by accident. I can remember only one time when something like that happened. On the very last day, the guys who were in last place hacked a bank and stole a pile of money. That earned them an enormous number of points, and they shot from last place straight into first.

But even then, you can’t chalk it all up to chance. I’m sure the team had a strategy of its own, and they still had to think fast and make decisions on the fly.

It’s a very serious intellectual competition. So you need some very serious skills to win or even finish near the top of the leaderboard.

And besides being a highly skilled hacker yourself, you also have to know how to play as a team. We also have a very strong captain, a formidable roster, and an extremely well-organized operation. I haven’t competed with the guys for three years now, but they keep winning. They’re eight-time champions, and that says a great deal.

– If someone wants to become a hacker, what do they actually need to do to get into the profession?

– That’s a good question. The truth is, hacking, like any other profession, has a number of different fields. Some people look for vulnerabilities in existing software. They’re reverse engineers. Others work with websites and infrastructure. They’re pentesters. There are plenty of other specializations as well, and everyone has their own area of expertise. So, to answer the question of how to become a hacker, I’d say everyone takes their own path.

Personally, I spent time on forums, regularly took part in competitions, read extensively, and later started writing articles myself. More broadly, a hacker needs knowledge across a wide range of areas. That means programming and system administration. You need to understand how operating systems work. Beyond that, you also need certain adjacent skills.

A hacker is someone who looks at a system but doesn’t take it at face value. They’re always thinking, “What could be wrong here?” So, in many ways, it’s a creative profession.

Competitions Remove the Constraints

– What do hacking competitions give a professional that they simply can’t get from a regular job or at a university? And conversely, where do CTF skills fall short when it comes to real-world cybersecurity?

– If we’re talking about good technical universities, they give you a solid foundation in mathematics. Math underpins a lot of fields – cryptography, machine learning, and artificial intelligence. But universities don’t teach you how to hack. A hacker is, first and foremost, self-taught.

Competitions, on the other hand, give you breadth, so to speak. You show up at a competition and immediately see a whole range of different services, along with a million different ways they could be hacked. Even if you work for a huge company with enormous resources, you’re still going to be constrained by corporate considerations. At a competition, nothing holds you back. There’s also an important reputational aspect. If you win or finish among the top teams, you make a name for yourself.

And then, of course, there are the skills. Why have the guys on the same team won eight times already? Because they’ve learned a lot. They know how these competitions work, what to expect, where they need to go first and where they need to go next. Competitions develop systematic thinking. The first time we entered one, everything we did was chaotic. We finished either 14th or 15th. But we’ve taken first place eight years in a row now because, after that first competition, we learned from our mistakes.

– Does the team roster stay stable, or does it change?

– The core group always stays stable. Of course, some people join and others leave. Take me, for example. I left, and someone else took my place. But the core team – the captains and vice-captains – has been competing together consistently for many years.

Every Hacker Is a Researcher

– Over the years, you’ve discovered vulnerabilities that were assigned CVEs, and you’ve published research papers. How did your thinking change when you moved from solving problems set by others to independently searching for new vulnerabilities?

– I wouldn’t say one led to the other. They were always happening in parallel, really. To find a vulnerability, you have to do some research. I mean, what is a CVE? It’s a vulnerability that nobody anywhere in the world has ever found before you. You’re the one who discovers it.

The circumstances in which I found my first CVE were actually pretty funny. At the time, I was working for a large media holding company, and my job was to research cloud technologies. We were using a system called SaltStack.

Then we had a company party at work. We had a great time, and afterward I didn’t feel like going home. I thought, “Why don’t I go get some work done?” So I went and worked through the night. And that happened to be the very night I found that CVE. Completely by accident. I’d found a way to bypass authentication in a major system responsible for managing all the other servers.

Luck helped a little. But you also need experience and persistence. You sit there, probing the system from different angles, studying the documentation and how it works, constantly trying things and looking for unconventional approaches. In other words, hackers do research, too.

In recent years, I’ve been focusing more on machine learning. That’s where there’s much more actual research involved.

– Which do you find more interesting?

– Well, these days I’d say I’m more interested in building things than breaking them. Because by the time you’ve found, say, your two-thousandth vulnerability, the rush is gone. It becomes routine. You know the process, you know what to expect. But this is something new. You start bringing machine learning into the mix, and you start training it to hack. A new era is beginning.

Companies Need Their Defenses Tested

– If it’s not a secret, which well-known Russian companies are you working with now? And which of the country’s market giants are most interested in having vulnerabilities found in their systems?

– All large companies are interested in that one way or another. What’s more, some are actually required to undergo these procedures because regulations mandate them. Others come to us simply because they genuinely care about their security.

As for the major players, we’ve worked with virtually all the large companies whose services are used by tens of millions of people every day. That includes Big Tech companies as well as midsize businesses.

– And how do companies react when they actually get hacked?

– The reality is that everyone is a target. That’s precisely why you need a security professional, which is the role I play. What does that job come down to? First, even if you do get hacked, you need to find out quickly and respond as fast as possible. Second, you need to make the cost of an attack higher than the potential payoff for the attacker, so that, in principle, attacking you simply isn’t worth their while.

And, of course, you need to prevent successful breaches in the first place. That means fixing your vulnerabilities, securing your perimeter, deploying security systems, and keeping all of it properly maintained.

AI Is Changing the Market

– Do you get the sense today that the cybersecurity industry is too focused on tools – scanners, frameworks, AI, automation – and not focused enough on a fundamental understanding of how systems actually work? In other words, are company executives shifting cybersecurity out of the hands of human professionals and into the “hands” of software?

– You can’t stop progress. It’s always been there, it’s here now, and it always will be. New tools will keep emerging. AI will get smarter and expand its capabilities, so the right strategy for a security professional isn’t to resist it but to lead the way. Security professionals simply have no choice anymore but to incorporate these tools into their work. And they need to configure them to catch the very same AI agents that have been programmed to cause harm.

– But how has AI actually affected cybersecurity?

– It has completely changed the field. I mean, if security was built around people just yesterday, today it’s being built around AI. I believe that within the next five years, security professionals who don’t understand AI and machine learning will become outsiders.

The market is different now, processes move faster, and there’s much more automation, but the threat landscape has expanded as well. AI systems themselves have vulnerabilities. And now attackers aren’t just hacking the kinds of services we’re used to, like ride-hailing or delivery platforms. They’re hacking AI itself, making it do things it was never designed to do. And that’s where new attacks, new threats, new challenges, and new technologies emerge – technologies for finding, detecting, and eliminating those threats.

– So could AI, in principle, actually surpass hackers?

– It already has. That’s already happened!

– Are there documented cases?

– Yes. There have been cases where AI found a major vulnerability that nobody had ever discovered before. AI is already finding vulnerabilities on its own.

More High-Quality Projects Needed

– You founded G-HACK and GSPARK. What led you to start your own ventures? What did you think was missing from the market or the existing educational ecosystem?

– My first company, G-HACK, focuses on pentesting, and it addresses one of the market’s major, highly visible problems: there simply aren’t enough projects done to a truly high standard. There are far too many cases where a company comes in to do a project and does a poor job. What do I mean by poor? They build a piece of software, run a few scanners against it, and manually fix a few bugs. But there’s no real research involved – no digging deep into a particular service, figuring out how it works, reading through the documentation. That’s exactly the kind of service I wanted to bring to the market.

As for GSPARK, that’s pretty straightforward. Everyone needs AI now, and there isn’t enough expertise on the market. It interests me, it’s what I work on, so I decided to monetize that expertise and sell it.

Where to Start

– If someone with no experience came to you today and said, “I want to become a cybersecurity professional,” what would you recommend? What should they learn first, and what definitely isn’t worth their time?

– If someone comes in with absolutely no IT experience, the first thing I’d tell them is: learn the fundamentals. Understand what a computer actually is, what it consists of, and how it’s put together. There are plenty of good books covering what we broadly call computer science – books on operating systems and computer networks. In other words, you need to learn the fundamentals: how computers work, how the internet works, and what protocols are.

Once you’ve learned the fundamentals, you can start becoming a hacker. That’s when you begin studying vulnerabilities, but under no circumstances should it be purely theoretical. You need hands-on practice. There are plenty of specialized platforms for that – Russia’s Standoff, or international platforms such as Hack The Box and Root Me. That’s where you can develop practical skills working with vulnerabilities.

That’s really the essence of being a hacker. The more you’ve seen and the more you’ve broken, the more you’re capable of breaking. You develop a feel for it and start looking for new approaches. And the broader your exposure, the better a hacker you become.

– Is a hacker a lone wolf, or is it better to work as part of a team?

– It depends on what you’re working on. If you’re hacking some random guy’s blog, you can probably handle that on your own. But serious, large-scale projects always involve a team because, as I said earlier, hackers have their own specializations too. Some are good at infrastructure, others are good at web security, and so on. If you’re dealing with a major client or a large project, you generally need all of those skills. So you send in a team.

Often, you have to hack a large number of targets – domains, subdomains, servers, systems. One person simply can’t get through all of that in the time available. That’s why you need a team. It’s also important to remember that the attackers we’re up against don’t work alone either. These are serious professional teams.

– You’ve spoken at more than 100 scientific and industry conferences. How has your audience changed in recent years? Has it developed a better understanding of the technical side of cybersecurity, or has demand instead shifted increasingly toward simple, quick solutions?

– Well, naturally, the level of expertise has gone up. You can clearly see the difference between ten years ago, when I started speaking at conferences, and today. The complexity of the topics has increased many times over. What people were discussing back then is now seen as the ABCs. That’s because systems evolve, and approaches change with them.

Today, every new conference appearance or presentation demands a deeper level of knowledge. And the audience, accordingly, comes in much better prepared.

Myths With a Germ of Truth

– Which myth about hackers and information security annoys you the most? And which one, on the other hand, strikes you as surprisingly true?

– I’ll start with the annoying ones. A lot of people think a hacker is a human Swiss Army knife. In other words, once you tell people you’re a hacker, they immediately come to you with questions like, “My phone isn’t working,” or “My Windows is broken,” or “Hey, my VKontakte account got hacked. What do I do? How did they hack me?” Very few people understand that every hack requires an investigation – entire teams work on these things! That’s probably what gets a little annoying.

There’s another stereotype. Tell an ordinary person you’re a hacker, and they immediately picture some villain who goes around breaking into things. Although that perception is gradually changing. These days, when you say “hacker,” people are increasingly likely to see you as a smart guy rather than some hooded cybercriminal.

The idea that a hacker might need only a minute to break into a system is a little closer to the truth. Movies play with that one all the time. Most of the time, it’s a myth, but sometimes it can be true – if you know about a specific vulnerability in the system and it can actually be exploited. But acquiring that knowledge takes a lot of time, too. Sometimes months or years. And there’s an important caveat: in practice, hacking a single target also takes a considerable amount of time on average.

– These days, everyone says cybersecurity has reached a point where you’re unlikely to stumble across a serious vulnerability by accident anymore. Is that true?

– That’s a misconception. You can find a vulnerability deliberately or completely by accident. In the first case, you have to study the system extensively and dig deep. Or you might accidentally put a space somewhere and suddenly find yourself in the admin panel. In fact, I have a friend, a well-known and talented Russian hacker who goes by the handle bo0om, and that’s exactly how he hacked a very large task-tracking system.

– Over the course of your career, you’ve been a competition participant, researcher, teacher, analyst, and entrepreneur. Which of those roles do you enjoy the most?

– Right now, I’m an entrepreneur, and so far that’s the role I enjoy most. But again, I haven’t given up research, and I still teach as well. What interests me most these days is putting together a team, building projects, and tackling strategic questions.

Over the next five years, I see myself primarily in management. I’ll leave the technical work to our terrific young people, who are already coming up, building their knowledge and gaining experience. In time, I’m sure some of them will end up working with us.

Why Machine Learning Matters

– If you look five to ten years ahead in cybersecurity, what worries you most? Is there a threat that both security professionals and businesses are underestimating today?

– Yes, we’ve already touched on it – AI. The advice I give all young people now is: learn machine learning. It’s a fundamental field. When you work with neural networks, it’s not enough just to know how to write a prompt for a bot – you need to understand how they actually work. You need to know what machine learning is, what types of neural networks there are, and how they relate to one another. That’s the most important investment you can make right now. Because five years from now, everything will run through AI.

All of this is developing incredibly fast right now, and it’s a seriously underestimated field. Accordingly, it’s underestimated in cybersecurity as well, because solutions are only just beginning to emerge – and at a fairly slow pace. Companies aren’t adopting these technologies as quickly as you’d want them to. But it’s going to take off in the near future. And these same technologies could be turned against companies. That’s why we need to start preparing and doing something about it right now.

– So someone who starts seriously studying machine learning today could fundamentally reshape the entire market five years from now?

– That’s exactly what’s going to happen! I’d even say the market will reshape itself. You can already feel it happening. Just look at the job market today – everywhere you look, employers are asking for LLM knowledge, the ability to work with them, and expertise in large language models.

– And finally, imagine you’re back at the beginning and you’re 18 again. Knowing everything you know today, what would you do differently?

– Well, the first thing I’d tell myself is, “Buy Bitcoin.” The second thing I’d tell myself is, “Start taking vitamins now.” That’s on the health side. And the third thing, professionally, I’d tell myself is, “Invest everything in machine learning.” Even back then. That’s what I’d do.

– Was that even possible back then?

– ML technologies emerged around 15 years ago.

– So you should have gone straight into that field?

– Yes and no. I could have pursued both ML and hacking. But the really good ML people – the ones who have focused specifically on machine learning – have already achieved a great deal. After devoting many years to it, they’re, in my view, much smarter, more accomplished, and frankly, much cooler today.

like
heart
fun
wow
sad
angry
Latest news
Important
Recommended
previous
next