Key facts at a glance
| Outcome | EB-1A approval for a Romanian malware defense researcher working at a U.S. based cybersecurity lab. |
| Approval date | Approved on September 24, 2024. |
| Field niche | AI-assisted malware attribution for critical infrastructure defense and faster incident analysis. |
| Starting problem | His technical outputs were strong, but most recognition stayed inside the lab and the record did not clearly show influence beyond one employer. |
| Path used | Ethical EB-1A profile building through focused malware-analysis papers, open-source detection-tool evidence, a CISA-facing critical-infrastructure white paper, technical-program and conference review roles, expert media commentary after cyber incidents, peer review, selective professional membership, and independent letters from malware and infrastructure ssdszsecurity leaders. |
| USCIS EB-1A criteria activated | Original contributions, scholarly articles, published material, judging, and memberships. |
On September 24, 2024, his Form I-140 was approved. EB-1A malware researcher cases often begin with work that happens after something has already gone wrong. Malware attribution begins after a malicious tool is found. An intrusion is investigated. Code has been modified, packed, reused, or deliberately made to resemble something else. The analyst has to decide which technical clues matter and which ones were planted to mislead. His research used artificial intelligence to help organize that problem. Inside a U.S. cybersecurity lab, colleagues understood the value of his malware-analysis work. Outside the lab, his name had little visibility.
Why did a strong malware research record still look too internal?
A researcher may build detection methods, study malware behavior, compare code features, or help analysts classify threats while the most interesting details remain inside protected systems and incident workflows.
The EB-1A green card is a self-petition immigrant category for people who can demonstrate extraordinary ability through sustained national or international acclaim and evidence placing them among the small percentage at the top of their field.
There was limited public material about him. He had not built a meaningful judging record. Independent experts outside the employer had not been brought together to explain his contribution. The technical work also risked reading like research performed for one cybersecurity lab. The strategy had to prove that the work mattered beyond one employer.
The turning point was choosing malware attribution, not cybersecurity, as the field
Even malware research could have stretched across reverse engineering, detection, sandboxing, threat intelligence, incident response, and software security.
Legal strategists and cybersecurity domain experts identified a narrower technical center: AI-assisted malware attribution for critical infrastructure defense.
Attribution in this context did not mean making public accusations about a country or criminal group. The profile focused on technical attribution: using code, behavior, infrastructure, feature patterns, and other evidence to help distinguish malware families, relate samples, and improve incident analysis.
When operational technology, utilities, transportation systems, or other essential services face a cyber incident, defenders need useful technical information quickly. Understanding whether malicious software resembles known families or shares meaningful characteristics can help structure investigation and defensive response.
How can AI help analysts compare malicious software without allowing superficial similarity to become false confidence?
What did USCIS need to see in this EB-1A malware-defense case?
USCIS needed to see an individual contribution with recognized significance, not simply a researcher employed by a respected cybersecurity lab.
At the first step of EB-1A review, the evidence must satisfy the applicable regulatory criteria. The final-merits review then considers the record as a whole and whether it shows the required extraordinary ability and sustained acclaim.
For original contributions, the petition had to explain his own malware-attribution methods and the technical value of the open-source detection tool. A GitHub repository or software release, by itself, would not prove major significance.
The record needed evidence showing that the tool and methods were useful beyond his immediate employer. Non-confidential documentation, outside use or adoption evidence where available, technical references, and independent expert analysis helped explain why the contribution had field relevance.
For judging, a conference title was not enough. Committee or program activity mattered only where he actually evaluated submissions, research, or technical work by others. Peer review was documented separately through real review activity.
For published material, his own malware papers belonged under scholarly authorship. The media criterion required coverage about him, his work, or his expertise.
For membership, the petition needed the organization's actual admission standards. A cybersecurity association open to anyone who paid dues could not be presented as a selective extraordinary-ability membership.
The final question was specific: had his malware-attribution work become recognized outside the lab that employed him?
The open-source tool gave outside experts something they could inspect
The team organized the non-confidential technical documentation around what the tool did, the malware-analysis problem it addressed, and the applicant's individual role in developing the approach.
The evidence therefore focused on external use, technical engagement, references, or other indications of value where the record supported them. Independent malware researchers could examine the tool's purpose and explain why the underlying method mattered.
USCIS no longer had to rely only on an employer description saying the researcher had done important work.
Part of the work could be inspected, discussed, and evaluated outside the lab.
The publication strategy separated attribution science from cyber headlines
With support from domain PhDs and technical research professionals, the authorship plan concentrated on malware analysis, AI-assisted attribution, feature comparison, and the limits of automated classification.
AI malware attribution can create false confidence if a model learns superficial artifacts, packaging behavior, or dataset shortcuts rather than meaningful technical relationships. His public work needed to show that he understood both the promise and the limits of AI in this field.
Why did the CISA-facing white paper matter, and what did it not claim?
It was designed for professionals who follow federal cyber-defense priorities, CISA-facing stakeholders, and organizations responsible for essential services.
The paper discussed how AI-assisted malware comparison could support analysis, where human validation remained necessary, and why technical attribution evidence should be communicated carefully during critical-infrastructure incidents.
The document did not claim CISA endorsement, adoption, or authorship. The purpose was to create a credible policy-and-operations bridge between malware research and the needs of infrastructure defenders.
It gave the client a field-facing document that incident-response leaders, security teams, and public-sector cyber professionals could understand without reading a laboratory paper.
Expert quotes after cyber incidents changed who could see him
After major cyber incidents entered the news cycle, journalists and technical outlets sought expert explanations about malware families, attribution confidence, AI-assisted analysis, and the risks of drawing conclusions too quickly.
He did not claim to know who was responsible for an incident when public evidence did not support that conclusion. He explained what technical analysts look for, why malware code can share features, and why attribution should separate evidence from speculation.
Published material about his expertise showed independent visibility around the same niche the petition claimed. He was becoming known for explaining a difficult cyber question without turning uncertainty into a headline.
Conference review roles and peer review turned technical expertise into judging evidence
Conference and technical-program roles were documented where he actually reviewed submissions, assessed proposed research, or helped evaluate technical content.
Peer-review assignments added a second form of judging evidence. Journals invited him to review work in malware analysis, cybersecurity, machine learning, or closely related technical areas.
Attending a conference is not judging. Sitting on a committee does not automatically prove judging. The record had to show actual evaluation of the work of others.
Independent letters explained why use beyond one employer mattered
Immignis developed a referee strategy around malware researchers, threat-analysis specialists, and critical-infrastructure security professionals who could understand the work without relying on the employer's reputation.
Malicious code can be reused, changed, obscured, or intentionally made confusing. AI can help analysts compare large amounts of technical information, but the value depends on the quality of the methodology and the way results are interpreted.
They discussed his attribution research, the open-source tool, the field-facing white paper, and the usefulness of his approach outside one internal project.
Advance My Profile prepared evidence-based drafts for expert review. Referees could revise the text and sign only what they considered accurate.
Why was ethical profile building essential in malware research?
An open-source tool can be inspected. A paper can be reproduced or challenged. A conference role can be verified. A selective membership can be compared with its real admission rules.
Fake awards, paid citations, predatory journals, invented judging roles, or exaggerated government relationships are especially dangerous in a field built around verification and trust.
That is why the profile did not pretend that a CISA-facing white paper was a CISA project. It did not convert committee attendance into judging. It did not call a public repository significant without evidence supporting the claim.
Do not build a cyber profile that creates a new risk to your own professional credibility.
Which USCIS EB-1A criteria did the final Form I-140 petition activate?
Original contributions: Malware-attribution research, open-source detection-tool evidence, external field-use context, and independent expert letters explained his individual contribution and why the work mattered beyond one cybersecurity lab.
Scholarly articles: Focused publications connected his authorship to AI-assisted malware attribution, technical malware comparison, and critical-infrastructure defense.
Published material: Independent media coverage and expert quotations discussed his work and expertise in malware analysis and attribution, creating public recognition around the defined niche.
Judging the work of others: Technical-program review activity, conference submission evaluation, and peer-review assignments documented genuine evaluation of work by other cybersecurity and malware specialists.
Memberships: Selective professional membership evidence was supported with the organization's admission or advancement standards and documentation showing how his qualifications were evaluated.
The papers showed technical depth. The open-source tool made part of the work inspectable. The critical-infrastructure white paper translated research for operational audiences. Media commentary created independent visibility. Conference review and peer review showed evaluative trust. Selective membership and independent letters added recognition outside the employer.
What did the September 2024 EB-1A approval mean?
USCIS approved the Form I-140 on September 24, 2024. The displayed case history shows receipt of the petition on July 31, active review on August 2, and approval on September 24. It does not show a request for additional evidence.
He had focused malware-analysis publications, open-source tool evidence, a critical-infrastructure white paper, conference review roles, expert media visibility, peer-review activity, selective professional membership, and independent letters from cyber specialists.

The approval gave him an EB-1A self-petition path without employer sponsorship or labor certification.
A journalist could identify the cyber question he understood. A conference could trust him to evaluate technical work. A critical-infrastructure audience could read his analysis. Independent experts could discuss a contribution that existed beyond the employer's walls.
The immigration result was approval. The career result was field recognition that could travel with him.
If your cybersecurity work is strong but almost invisible outside your employer
You may have built detection systems, investigated malware, improved incident workflows, or developed internal security methods without creating a public authority record.
Protect confidential incident details. Document non-confidential methods. Publish around the problem you actually solve. Create field-facing technical resources where appropriate. Accept real judging opportunities. Let independent experts explain significance they can genuinely evaluate. Build credible recognition around the work you can defend.
FAQ
Can an open-source malware tool support an EB-1A original-contribution claim?
Yes, when the applicant can show an individual technical contribution and evidence that the tool or underlying method has recognized significance. A public repository alone is not enough. External use, technical engagement, references, adoption context, and independent expert analysis may help explain why the contribution matters beyond the applicant's employer.
How can a malware researcher prove impact beyond one cybersecurity company or lab?
The record can use non-confidential open-source evidence, independent technical references, focused publications, external use or adoption documentation where available, media coverage, conference roles, peer review, and independent expert letters. The goal is to show that the applicant's work can be recognized and evaluated without relying only on an employer's internal description.
Does a paper written by the applicant count as published material about them?
Not under the published-material criterion merely because it was published. The applicant's own scholarly papers may support the authorship criterion. Published material generally needs to be about the applicant and the applicant's work in the field, subject to USCIS's evidentiary requirements for that criterion.
Can a conference committee role count as judging for EB-1A?
It can support judging when the applicant actually evaluates submissions, research, technical proposals, or other professionals' work. A committee title by itself is not enough. The petition should document the evaluation activity and the type of work the applicant was asked to judge.
Does a CISA-facing cybersecurity white paper mean CISA endorsed the applicant?
No. A white paper prepared for critical-infrastructure or CISA-facing audiences should not be described as CISA-endorsed unless there is real evidence of endorsement or official adoption. The document may still be useful as field-facing analysis when it addresses cyber-defense problems relevant to infrastructure stakeholders.
Do I need a U.S. cybersecurity degree to qualify for EB-1A as a malware researcher?
No specific U.S. degree is required for the EB-1A extraordinary ability category. Education can support technical expertise, but USCIS evaluates the extraordinary-ability evidence and the record as a whole. Original contributions, focused authorship, judging, qualifying memberships, published material, and sustained independent recognition may all be relevant.
Build an EB-1A success story around cybersecurity work the field can verify
If you work in malware analysis, threat research, AI security, critical-infrastructure defense, incident response, or another advanced cybersecurity field, your strongest contributions may be hidden inside protected environments.
Immignis and Advance My Profile help professionals identify a defensible niche, build credible public recognition around real technical work, document individual impact, and prepare an EB-1A record that can withstand professional and immigration scrutiny.