Malware intelligence
What is malware intelligence?
Malware intelligence is the analysis of malicious software as evidence about the people who build, sell, and operate it — including which family (a specific strain or lineage of malicious software with its own codebase and features) a sample belongs to, who runs it, how it is distributed and monetized, and what infrastructure and payment destinations it connects to.
A file hash, detection signature, and sandbox report are data. Knowing which family that sample belongs to, which affiliate identifier is embedded in the build, which control panel it reports to, where that panel is hosted, which forum sells access to it, and where the proceeds are directed is intelligence.
Malware intelligence is one input to cyber threat intelligence (CTI), which sits on the detection side of the table above, and to all-source investigations, which is where malware evidence gets fused with financial, identity, and open-source evidence into a single case.
{{horizontal-line}}
How does malware intelligence work?
The process runs through four stages, typically looping constantly.
1. Identification and family classification
This stage determines which known family a sample belongs to, drawing on vendor and community classifications, published family reporting, shared code and packing characteristics, and infrastructure reuse. Classification is a judgment, as two competent teams can classify the same sample differently.
2. Configuration extraction and what it reveals
A malware build carries settings chosen by its operator. Depending on the family, those settings can include command-and-control addresses or domains, campaign and build identifiers, affiliate or partner tags, and target and exclusion lists, including geographic exclusions that hint at where the operator lives or where they avoid drawing attention. Financially motivated families often hardcode payment destinations directly into the build. A configuration is the closest thing to a statement by the operator that an investigator gets from the code itself.
3. Infrastructure and distribution mapping
This stage maps where control panels are hosted, which hosting providers and resellers recur, how loaders hand off to payloads, and which channels distribute the malware. Access to a network is frequently sold and resold, so the crew that gains initial access is often not the crew that monetizes it.
4. Economy and monetization analysis
This stage covers how a family is sold and how the money moves: subscription and licensing models, affiliate splits, negotiation and payment behavior, and where proceeds are directed. It's the stage that connects malware evidence to financial evidence.
{{horizontal-line}}
How does the malware economy work?
Malware families are sold as products, not distributed as tools. Each element below is a separate person, crew, or mechanism, and each is a separate investigative target.
{{horizontal-line}}
Why do malware family names disagree across vendors?
Different vendors discover the same family at different times, name it from different evidence — a string in the binary, a campaign, an internal codename, a house naming convention — and publish on their own schedules, with commercial incentive to keep their own naming intact. Community efforts to map aliases across vendors exist and help, but no authoritative registry exists.
That mismatch creates two distinct risks:
- Two reports about differently named families may describe the same operation, which produces duplicated work and a case that looks weaker than it is because the evidence is split across two names.
- Two reports using the same name may describe different operators, which is the more dangerous error and happens routinely with families sold as a service to many affiliates.
The operational fix is to track the family by durable artifacts — infrastructure, configuration patterns, payment destinations, behavior — and treat the name as a label attached to that cluster, not as the identity of it.
{{horizontal-line}}
Why is malware intelligence important?
Malware is the most reused asset in the criminal economy. The same family, panel, hosting, and payment paths recur across many otherwise unconnected incidents, which makes malware one of the few artifacts that can reliably link separate cases to a single organization.
{{horizontal-line}}
How are AI and agentic crime changing malware intelligence?
AI is changing both sides of this discipline.
On the offensive side, it lowers the skill floor for building and modifying malware, accelerates variant generation so that superficially distinct samples can be produced continuously, generates convincing delivery content across languages, and shortens the cycle time on standing up and rebuilding infrastructure. Variant volume defeats sample-level tracking far faster than it defeats family-level and economy-level tracking.
On the investigative side, it enables automated triage and clustering across sample volumes no analyst could review manually, cross-language processing of operator communications and negotiation transcripts, faster extraction and normalization of configuration data across families, and multi-hop pivoting from a family to an address to an entity in a single query rather than a week of manual correlation.
AI-enabled crime refers to the use of machine learning, automation, and artificial intelligence techniques to facilitate, scale, or conceal illegal operations. Learn more here.
{{horizontal-line}}
Who uses malware intelligence?
{{horizontal-line}}
What sources feed malware intelligence?
{{horizontal-line}}
What are the challenges of malware intelligence?
{{horizontal-line}}
Frequently asked questions (FAQs)
1. What is the difference between malware intelligence and malware analysis?
Malware analysis examines a sample to determine what it does — its behavior, capabilities, and how to detect it. Malware intelligence uses samples, infrastructure, venues, and payments to determine who operates the malware and how their business works. Analysis is sample-focused and detection-oriented; intelligence is operator-focused and investigation-oriented.
2. Is malware intelligence part of cyber threat intelligence?
It's one input to CTI, and also to criminal investigations, sanctions work, and financial crime analysis. CTI teams use malware intelligence to prioritize which threats matter most, not just to catalog indicators.
3. How does malware-as-a-service work?
A developer builds and maintains the malware family. An affiliate deploys it against targets under a revenue-share agreement. An access broker supplies the initial foothold. A host keeps the supporting infrastructure running. A launderer moves the proceeds. Each role is a distinct investigative target.
4. What does a malware configuration reveal?
A configuration can reveal command-and-control addresses, campaign and affiliate identifiers, target and exclusion lists, and, in financially motivated families, hardcoded payment destinations. Each of these reflects a decision the operator made when building or customizing the sample.
5. Why do different vendors use different names for the same malware?
Vendors discover and name families independently, based on whatever evidence they collect first, and no shared registry reconciles the results. The practical consequence is that investigators need to track families by durable artifacts, such as infrastructure and payment patterns, rather than by name alone.
6. Can malware be attributed to a specific group or person?
Frequently, yes, through infrastructure reuse, configuration artifacts, operational mistakes, payment paths, and corroboration against official records such as indictments or designations. Code similarity alone is not sufficient, since code is sold, leaked, and copied across unrelated operators.
7. How do investigators follow the money from a malware operation?
Payment destinations drawn from configurations, extortion negotiations, and marketplace settlement records become the starting point for tracing where proceeds went. That trail is what connects a malware family, which is a technical artifact, to an organization with real-world assets and participants.
8. Is malware intelligence the same as infostealer or stealer log data?
No. Stealer logs are the output of one malware category and are used to identify exposed victims and compromised credentials. Malware intelligence covers the family that produced those logs and the operator running it, including how the family is built, sold, and monetized.
Access our coverage of TRON, Solana and 23 other blockchains
Fill out the form to speak with our team about investigative professional services.



















