0 m
MALWAREBOX / RESEARCH

Indicators rotate.
Actors don't.

Actor-centric, not IOC-centric. Our own models for infrastructure, attribution and defensive prioritization, built in the gaps that ATT&CK, STIX, NIST and FAIR leave open on purpose.

RESEARCH FRAMEWORKS

Our frameworks, one research program

Each framework closes a gap that ATT&CK, STIX, the Diamond Model, NIST CSF or FAIR leave open by design. The analyses and the IIM feed below are evidence: proof these models hold up against real campaigns, not the main event.

IIM: Infrastructure Intelligence Model
v1.1 Draft CC BY 4.0
Indicators rotate. Actors don't. Infrastructure patterns outlive both.

A structural grammar for adversary infrastructure, positioned between short-lived IOCs and the deliberately abstract ATT&CK. Five layers: Entities (raw observation) to Relations to Roles (5 types: entry, redirector, staging, payload, c2) to Techniques (26, across 5 categories: Hosting, Resolution, Routing, Gating, Composition) to Chains and Patterns. Complementary to ATT&CK, to STIX 2.1 (lossless export) and to the Diamond Model, for which it supplies the missing grammar for the Infrastructure vertex. Technique catalog v1.0 released.

entry (phishing lure) staging (Telegram dead drop) payload (Vidar v2 via Xray/VLESS/REALITY) c2 (self-signed mTLS implant)

GhostShell (MB-0009): a standalone EC-P-256 mTLS implant with per-implant client certificates and a self-named CA, tracked after publication by Zscaler ThreatLabz and the Belgian CCB. IIM techniques also carry longitudinal cases such as Gamaredon’s BITS-downloading (MB-0001) and the GIFTEDCROOK tooling evolution across UAC-0226 (MB-0004).

Dost, R. (2026). Infrastructure Intelligence Model (IIM). Malwarebox Research.
iim.malwarebox.eu
IIMQL: Infrastructure Intelligence Model Query Language
v1.0 Apache 2.0
Structural questions against IIM data, not ad hoc Python.

A query language for IIM data, drawing on Cypher's graph pattern matching and SQL's filtering, built for the IIM v1.1 data model: MATCH (e:entry)-[:download]->(s:staging)-->(p:payload)-[:connect]->(c:c2) WHERE ... RETURN ... Ships as CLI, REPL and Python API, with no runtime dependencies beyond stdlib. 25 end-to-end tests.

iimql.malwarebox.eu
SOLBIT: Deception-Aware Attribution
Model + scoring open
Attribution weighted by how hard evidence is to fake.

Six dimensions of evidence, weighted by forgeability rather than treated as equal: Technical (easiest to fake) to Infrastructure to Linguistic to Behavioral to Operational to Strategic (hardest to fake: cui bono). A divergence between surface and deep dimensions reads as a false-flag signal, not noise to discard.

ACDP: Actor-Centric Defensive Prioritization
Released Full paper available
Which control comes first, against this actor specifically.

Sits above ATT&CK, NIST CSF and FAIR: takes their output and produces a reasoned order for which control comes first, against a specific actor. Four axes (ADV, IRR, CC, DDT), weighted per actor rather than generically. A worked example against a Sandworm profile puts immutable backups in Tier 1 and awareness training in Tier 4, against that actor, not in general.

Dost, R. (2026). Actor-Centric Defensive Prioritization (ACDP). Malwarebox Research.
acdp.malwarebox.eu
Modus: Decision Fingerprinting
Unreleased
An actor's stable operational choices (registrar and TLD preference, activity windows, rotation cadence), independent of tooling rotation.
MB-RM: Malwarebox Relevance Mapper
Unreleased
Maps an organization's exposure onto actor relevance.
TRACKED CLUSTERS

Compact reference: clusters under active tracking

CLUSTER
MB-ID
ORIGIN
TARGETS
ARTICLES
Gamaredon
MB-0001
🇷🇺 Russia
🇺🇦 Ukraine
7
APT28
MB-0002
🇷🇺 Russia
🇺🇦 Ukraine, NATO/EU
1
MuddyWater
MB-0003
🇮🇷 Iran
🇮🇶🇸🇦🇦🇪🇯🇴🇹🇷🇮🇱🇩🇪🇺🇸
3
UAC-0226
MB-0004
Unknown
🇺🇦 Ukraine
2
UAC-0184
MB-0005
Unknown
🇺🇦 Ukraine
2
UAC-0244 / UAC-0247
MB-0006
Unknown
🇺🇦 Ukraine
1
GhostShell
MB-0009
Unknown
🇺🇦 Ukraine (UAV / defense supply chain)
1
APT43
MB-0010
🇰🇵 North Korea
🇰🇷🇺🇸🇯🇵🇪🇺
1
IIM FEED
feed.iim.malwarebox.eu

Frameworks in production

40
Chains
19
Actors
24
Techniques observed
12
In review
CONFIDENCE
33 confirmed 7 likely 0 tentative
422 entities 457 relations last publication 30 Aug 2026

Community-submitted chains are accepted after review. A verifiable source link is required, capped at 1,000 submissions per day.

LAST PUBLISHED CHAINS
ALL 40
MB-0001 Gamaredon confirmed

IIM chain for Sekoia.io's three-part 'FSB's matryoshka' Gamaredon series (parts 1-3, 1-4 June 2026) reconstructing a January 2026 infection chain. A weaponized xHTML lure HTML-smuggles a malicious RAR that exploits CVE-2025-8088 to drop a hidden HTA…

entry staging×4 redirector×6 c2 payload×2 c2×2
16 entities 18 relations 9 techniques observed 03 Jun 2026
APT43 confirmed

ENKI-attributed Kimsuky lane. Fake Webex page based on a legitimate meeting schedule downloads an ALZip archive containing fix-camera.jse, which drops meeting.html and mTSTCv8.mdxm/loadDll.dll. The downloader retrieves engine.dat/spyInster.dll, which installs…

entry staging×2 redirector staging×2 payload×3 c2 staging
11 entities 13 relations 2 techniques observed 30 Apr 2026
GREYVIBE likely

WithSecure-attributed GREYVIBE PhantomMail lane. April 2026 spear-phishing likely impersonated Ukraine’s State Service of Special Communications and Information Protection, delivered Google Drive-hosted RAR archives, ran TEASOUP-obfuscated JavaScript loaders,…

entry redirector staging×2 payload×2 staging c2×6
13 entities 13 relations 3 techniques observed 30 Apr 2026
unattributed confirmed

IIM chain built from the original Rapid7 report published on 2026-05-29 and included here as an accepted follow-up for the 2026-05-31 request. Rapid7 observed exploitation of CVE-2026-0257 against PAN-OS / Prisma Access GlobalProtect deployments where…

entry×4 redirector staging payload×2 c2
9 entities 9 relations 0 techniques observed 29 May 2026
unattributed confirmed

IIM chain built from an original reverse-engineering report published on 2026-05-31. The report analyzes a Mach-O universal binary associated with Atomic macOS Stealer (AMOS). The sample uses a rolling XOR routine keyed by 7M43mJx9I0GwjslSA2oKSgkqsUo to hide…

entry staging payload c2×2
5 entities 4 relations 0 techniques observed 31 May 2026
unattributed confirmed in review

IIM chain for a targeted spear-phishing campaign reported via The Hacker News (Joe Security analysis) against the Punjab Safe Cities Authority and PPIC3 in Pakistan. The email used legitimate-sounding government infrastructure projects as lures and carried…

entry×2 staging payload c2
5 entities 4 relations 1 techniques observed 01 May 2026
Open Feed
IIM Workbench, a local tool for building, validating and STIX 2.1-exporting IIM chains, for anyone who wants to annotate their own.
Tracked with Kraken, our observation platform (1.0-eval "Hadal", restricted access)