MALWAREBOX / ABOUT

Independent European threat intelligence, built to stay traceable.

Malwarebox does research, actor tracking, tooling and education.

WHY MALWAREBOX EXISTS

Malwarebox came out of a simple observation. For malware analysis and threat intelligence there is no shortage of individual tools, but hardly any environment that connects technical findings, infrastructure, change over time and analytical assessment in a way that remains traceable.

Information sat spread across files, notes, feeds and separate platforms. The connections between them had to be reconstructed by hand and they lived in the head of whoever did the work rather than in the record. That made findings hard to revisit, hard to hand over and hard to check.

The frameworks and tools we publish exist to close that gap. A common structure for infrastructure intelligence, a query language for it and a platform that keeps the path from raw artefact to assessment visible. The methodology is public so the conclusions can be examined, not just read.

Research program Papers
WHAT WE DO
01 Research
Deep technical research on threats, malware and adversary tradecraft, published with the methodology attached.
Research program
02 Tracking
Long-term monitoring of threat actors, campaigns and infrastructure. One dossier per actor, with an assigned Malwarebox ID.
Actor registry
03 Tooling
The frameworks and platforms the research runs on: IIM and IIMQL, Kraken and Mantis, published or specified in the open where possible.
Papers and specifications
04 Training
Practical education for analysts, defenders and people entering CTI. Netlab is the training platform, currently in development.
Netlab
PRINCIPLES
What the work commits to, in publications and in the platform alike.
Methodologies and code on GitHub
github.com/MalwareboxEU
European digital sovereignty
Independence from single vendors and investors
Openly accessible methodologies
Traceable attribution rather than asserted attribution
Source criticism and defensible evidence
Facts, hypotheses and assessments kept apart
Temporal context instead of isolated snapshots
Technical and strategic findings connected
Analytical transparency and reproducibility
COLLABORATION & INQUIRIES

We work with researchers, CERTs, vendors and academic groups where the exchange makes the analysis better. Write to us with the case, not just the interest.

All of it goes through one page: Work with us. Collaboration, a lead, a question about a method, press or wanting to do some of the work yourself. The form encrypts what you write in your browser before it is sent.

Research collaboration
Joint analysis, shared tracking of an actor or review of a methodology before publication.
Data and platform access
Access to Kraken, the IIM tooling or the closed substrate documented on request.
Teaching and talks
Workshops, lectures and conference talks on infrastructure intelligence and analysis practice.
CONTACT
EMAIL
contact@malwarebox.eu

Encrypted mail is welcome. Use the key below and include your own public key so we can reply in kind.

PGP FINGERPRINT
RSA 3072 · 2026-09-03
ED78 45E8 FED8 825C 3365 672D 0C48 2772 C9F2 35D1
Download public key
PRESS & CITATION

Our publications may be quoted and referenced. Please cite the specific publication and its version rather than the site as a whole, so readers can find the exact statement. Each framework carries a ready citation block on the Papers page.

CITE THE ORGANISATION AS
Malwarebox. Independent threat intelligence research. malwarebox.eu
Press inquiries: contact@malwarebox.eu
Citation blocks: Papers
Actor references: Actor registry