This blog is the research publication of the Malwarebox Threat Intelligence Initiative.
New analyses, investigations and notes from our work appear here first.
Malwarebox is an independent threat intelligence initiative based in Germany.
Our focus is threat actor-centric research – adversary infrastructure, tooling and operational patterns, observed over longer periods of time.
Tracked clusters get a Malwarebox ID (MB-XXXX) and are followed across campaigns.
Most of the work is based on open sources, our own honeypot and sensor infrastructure and hands-on malware analysis.
Recurring topics are the Russia/Ukraine nexus, procurement and sanctions networks and the hosting infrastructure behind malicious operations.
More about the initiative, our tools and how to work with us at malwarebox.eu.
Malwarebox is run by a small team.
Because of the nature of our work, not everyone involved appears publicly by name.
We are open to new contributors, whether you work in research, analysis or development.
You can contribute under your own name or stay anonymous, whichever suits you.
Get in touch via our work with us page or at contact@malwarebox.eu.
Show public key
-----BEGIN PGP PUBLIC KEY BLOCK----- mDMEaST5DRYJKwYBBAHaRw8BAQdAA3v5GiGqoak3Kwms9CZfGA7q1MZ5CqBdN59F 3zwi1960KlJvYmluIERvc3QgPHJvYmluLmRvc3RAc3luYXB0aWNzeXN0ZW1zLmRl PohyBBMWCAAaBAsJCAcCFQgCFgECGQEFgmkk+Q0CngECmwMACgkQ/BtMiZzVF7fK 8gEA8fTnCLkuAWpcv6KCdUGcg93KAchWQN2+8Y26L58z1tIA/ic7yl+5Lhjb/xgI R0D1fwCwcwjBXXmqOf4qX7UqWwsJuDgEaST5DRIKKwYBBAGXVQEFAQEHQCfvF2J2 YIUstYglrNBZRnpnbbh1Lusk1SLA6kptJyJVAwEIB4hhBBgWCAAJBYJpJPkNApsM AAoJEPwbTImc1Re3m/gA/Rc9xaGupoVs1EhGONZ2feTIRBZ/r/sWZ2fibVjvzQLZ AP9J4NpI8CTvKnvjy4I3bfjiS0EinUTCcGjI/tjoVRoTCw== =O1ZA -----END PGP PUBLIC KEY BLOCK-----
