The PolySwarm Blog

Analyze suspicious files and URLs, at scale, millions of times per day. Get real-time threat intel from a crowdsourced network of security experts and antivirus companies competing to protect you.

Russia-Ukraine Conflict and Cyberwar Implications

Feb 4, 2022 2:40:46 PM / by PolySwarm Team posted in Ukraine, Russia, Special Report

0 Comments

Overview

  • Ongoing political tensions between Russia and Ukraine are at a breaking point, with the US and other NATO nations preparing to assist Ukraine if a military conflict arises.
  • Russia and Ukraine have a long history of state-sponsored cyber conflicts, including both espionage and disruptive attacks.
  • Recent cyber activity targeting Ukraine includes multiple government website defacements and WhisperGate, a wiper malware disguised as ransomware. IOCs for PolySwarm’s samples of WhisperGate are provided.
  • Hacktivists recently attacked Belarus Railway to protest Russian troop transport and demand the release of “political prisoners.” This incident marked the first time hacktivists have leveraged ransomware in pursuit of political objectives.
  • The cyber struggle between Russia and Ukraine has the potential to spill over and have a real-world kinetic impact. Our analysts provide a list of implications.
Read More

NectarNet - NCT Token Rewards for Cyber Security Data

Jan 31, 2022 8:56:00 AM / by PolySwarm Team posted in Insider, Explained, Product

0 Comments

 

Read More

SecondWrite joins the PolySwarm marketplace

Jan 7, 2022 10:24:46 AM / by PolySwarm Team posted in Partner, Engine

0 Comments

“SecondWrite is excited to join Polyswarm’s marketplace as an engine. Our mission is to secure computers and networks using our market-leading technology to detect malware. Polyswarm enables us to reach a large community of users and provides us with additional recent samples for our threat intelligence.” stated Rajeev Barua, CEO of SecondWrite.

Read More

Emotet Banking Trojan Back in Action

Nov 30, 2021 3:25:13 PM / by PolySwarm Tech Team posted in PolySwarm, Threat Bulletin

0 Comments

Verticals Affected: Financial, Various
Victim Location: US, UK, Germany, Canada
Related Malware Families: TrickBot, Ryuk, QakBot, Zloader

A number of threat intelligence companies have recently reported on the return of the Emotet banking trojan. We first saw new variants of Emotet in our marketplace on November 15, 2021, before any industry in-depth analysis reports were released.

Read More

QiAnXin joins the PolySwarm marketplace

Sep 1, 2021 11:30:21 AM / by PolySwarm Team posted in Partner, Engine

0 Comments

"As a unique malware detection and threat intelligence data platform, PolySwarm's crowdsourced model substantially improves the ability to explore, enrich, and mine malware data, which directly benefits the infosec community. Qi An Xin is excited to partner with PolySwarm to continue to innovate” Liejun Wang, Director of Threat Intelligence at QiAnXin.

Read More

Why a New Engine Creation and Management Architecture?

Jun 16, 2021 11:57:47 AM / by Nick Davis posted in Explained, PolySwarm, Research

0 Comments

We recently completed the “New Engine Claiming and Management” milestone on our development roadmap. Our goal was to make it easier for Engine owners to build, configure and test an engine, and then join the PolySwarm Marketplace, so we’ve completely redesigned the architecture.

Read More

Security Telemetry: New utility use for Nectar (NCT)

May 17, 2021 6:05:27 PM / by PolySwarm Team posted in Explained, PolySwarm, Blockchain

0 Comments

Today we introduce a new utility use for PolySwarm’s Nectar token for average users: distributing rewards for security-relevant data about TLS certificates, DNS resolutions, and potentially malicious files encountered in daily computer use. Many of these telemetry sources are already collected from user devices by Antivirus (AV) providers. Still, there are a number of serious issues with how they are collected, how users are compensated for their information, and how these results are shared. By re-imagining how this marketplace works, we can increase collection transparency, fairly compensate all participants in the marketplace, and, most importantly, create a more unified source of security telemetry that will better protect users worldwide.

Read More

SentinelOne joins the PolySwarm marketplace

Apr 8, 2021 3:17:20 PM / by PolySwarm Team posted in Partner, Engine

0 Comments

 

SentinelOne joined PolySwarm’s marketplace, and their threat detection engine is now live. The US-based company, a pioneer in advanced endpoint protection, leverages machine learning designed to identify unknown malware and remediate threats in real-time.  

Read More

Subscribe to Email Updates

Lists by Topic

see all

Posts by Topic

See all

Recent Posts