all blogs

Explore our blog

AI SOC

3 min

Analyst firm SACR recognizes Intezer in the AI SOC category

What makes an AI SOC trustworthy? SACR's 2026 research points to evidence, context and verified action. See how Intezer was evaluated.

Zev Schonberg

Company News

4 min

Intezer Workflows. The AI SOC is now complete

Detect, triage, investigate, respond. The entire SOC lifecycle now runs in one platform with AI executing and humans supervising. 

Zev Schonberg

View Topics
SOAR
MDR
AI SOC
Detection Engineering
Threat Hunting
Threat Bulletin
The SecOps Automation Blog
SOC
Research
Malware Analysis
Knowledge Base
Incident Response
Company News
Cloud Security
CISO
Alert Triage
AI
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Reset
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Research

13 minutes

HiddenWasp Malware Stings Targeted Linux Systems

Intezer has discovered a new, sophisticated malware named HiddenWasp, targeting Linux systems. Unlike common Linux malware, HiddenWasp is not focused on crypto-mining or DDoS activity, but rather it is a trojan purely used for targeted remote control.

Research

6 minutes

Technical Analysis: Pacha Group Competing against Rocke Group for Cryptocurrency Mining Foothold on the Cloud

The Pacha Group is disabling previously installed cryptominers from other threat groups on the cloud, most notably Rocke Group, in order to obtain the largest foothold of computing power on the cloud for conducting malicious crypto-mining activities.

Research

3 minutes

War on the Cloud: Cybercriminals Competing for Cryptocurrency Mining Foothold

The Pacha Group is disabling previously installed cryptominers from other threat groups on the cloud, most notably the Rocke Group, in order to obtain the largest foothold of computing power on the cloud for conducting malicious crypto-mining activities.

Malware Analysis

7 minutes

Meet the Team: Shaul Holtzman

Get to know Intezer Analyze community manager Shaul Holtzman. Shaul is a former cybersecurity analyst helping organizations detect and classify advanced cyber threats.

Incident Response

6 minutes

Fileless Malware: Scanning Endpoint Memory with Genetic Analysis

Memory forensics are crucial for detecting fileless malware. The new Intezer endpoint analysis solution analyzes code in memory to detect advanced threats.

Research

9 minutes

Technical Analysis: Pacha Group Deploying Undetected Cryptojacking Campaigns on Linux Servers

A technical analysis of Linux.Greedy.Antd, a cryptominer employed by Pacha Group to compromise third party Linux servers. The malware was undetected by all leading engines, demonstrating the sophistication of this threat.

Alert Triage

4 minutes

New! API for the Intezer Analyze Community

Announcing the release of an API for the Intezer Analyze community edition. Members of the free community can now create automation scripts to analyze files without manual intervention. Highlighted in this blog are some of the ways in which community users can utilize the API.

Malware Analysis

4 minutes

What is Genetic Malware Analysis?

Software is evolutionary. Intezer has introduced a new innovative approach to automate malware analysis and provide clear insights into any suspicious file. The company's Genetic Malware Analysis technology empowers security teams to improve and accelerate all stages of their incident response, from the initial alert to the final step of remediation.

Research

14 minutes

ChinaZ Revelations: Revealing ChinaZ Relationships with other Chinese Threat Actor Groups

Distributed denial-of-service (DDoS) attacks were on the rise in 2018. Chinese threat actors in particular have predominantly deployed DDoS attacks in their cyber campaigns, and China has emerged has having one of the highest rates of DDoS attacks. This blog provides a technical analysis highlighting connections between ChinaZ and other notable Chinese threat actor groups in the current DDoS landscape.

Research

8 minutes

Muhstik Botnet Reloaded: New Variants Targeting phpMyAdmin Servers

The Muhstik botnet was first exposed by Netlab360 researchers in May 2018. This botnet targeted mainly GPON routers. At Intezer we found that Muhstik is extending its spectrum of compromised devices by targeting web servers hosting phpMyAdmin.

Research

3 minutes

Paleontology: The Unknown Origins of Lazarus Malware

As seen by security researchers across the world and proven in a joint research by McAfee and Intezer, Lazarus, one of the groups operating from North Korea, has consistently reused code in their malware toolset.

Research

2 minutes

APT37: Final1stspy Reaping the FreeMilk

Researchers at Palo Alto Networks recently published a report regarding the NOKKI malware, which has shared code with KONNI and, although not in the report by Palo Alto, KimJongRAT (discovered by Paul Rascagnères of Cisco Talos in 2013), and another report on how there is evidence of the NOKKI malware connecting...

Research

2 minutes

Intezer Analyze™ ELF Support Release: Hakai Variant Case Study

We would like to proudly announce that Intezer Analyze™ now supports genetic malware analysis for ELF binaries! You may now upload ELF files to our system and find code reuse. We have already indexed the genes of millions of different files into our ELF genome database, classified into both malicious, trusted, and...

Research

5 minutes

Prince of Persia: The Sands of Foudre

Foudre is a remote access tool and has the ability to remotely execute commands, steal information about the infected target (such as keystrokes, process information, etc), and auto-update itself. Most of the code and functionality from the previous versions of Foudre and Infy was reused and can be read about in the reports by Palo Alto linked above, so we are only going to focus on the new, unique, interesting features and the linkage of code reuse from previous versions.

Malware Analysis

4 minutes

Code, Strings and what’s in between

Our technology is based on genetic analysis of files. So far, we’ve focused mainly on detection of code reuse, as part of the genetic malware analysis process.