Earlier today I made a post about over 900 malware research papers being released in 2025. Some people expressed confusion about this. Let's talk about malware research, what it entails, blah blah blah.
Malware research can be broken down into two distinct categories and from there it can be broken down further into more unique categories. Let's keep it shrimple.
- Offensive malware research
- Defensive malware research
Offensive malware research is trying to find new malware techniques. This is pretty broad. I won't go too much into detail on this. This isn't the thingie we're discussing here.
Defensive malware research is documenting new malware campaigns, tracking existing malware campaigns, reverse engineering malware and correlating it and/or tying it to other malware campaigns, techniques on malware detection, etc. This can be pretty broad too because malware detection, malware campaigns, anti-malware research, etc. will be vastly different on Windows, Linux, MacOS, mobile-devices, etc.
When I write that there was 996 malware research papers released what it means is (approx.) "996 vendors released papers sharing information on malware campaigns, reverse engineering malware, sharing malware detection techniques, malware family lineage discoveries (shared code across malware campaigns), etc".
Every single day I see vendors release paper documenting malware campaigns, what they're seeing on their side, and methods to detect the malware payloads. How they're discovered is also a different discussion for a different day.
Places where malware research is released:
- Basically every government on the planet
- Hundreds of independent researchers
- Google
- SentinelOne
- ESET
- Microsoft
- Kaspersky
- CrowdStrike
- RecordedFuture
- Cisco Talos
- VMWare
- CloudFlare
- Akamai
- HuntressLabs
- BitDefender (also Huntress?)
- Fortinet
- AVAST / AVG
- TrendMicro
- Sophos
- F-secure
- Panda
- Comodo
- Qihoo
- Dr. Web
- NVIDIA
- Norton
- MalwareBytes
- Secureworks
- ZScaler
- Okta
- Chainalysis
- Trustwave
- Nextron Systems
- GDATA
- AT&T
- Walmart
- StealthMole
- Censys
- AhnLab
- PtSecurity
- OxSecurity
- Securonix
- Koi-AI
- Palo Alto Networks
- CheckPoint
- Huorong
- Oligo
- Cyderes
- DarkTrace
- K7Computing
- CyberArmor
- ... more ....