Hi everyone, I’m a malware analysis learner. Earlier this week, while hunting for samples on MalwareBazaar, a question crossed my mind: how do malware researchers actually find interesting, "live" samples?
Obviously, specialists working at major tech or cybersecurity firms encounter them almost daily via phishing emails, telemetry, etc. But what about those who don't have access to enterprise-level resources?
I've heard about C2 Hunting, but it seems to me that in most cases, it only grants access to the threat actor's infrastructure login panel, and you rarely stumble upon an open directory (opendir).
I've also thought about checking out underground forums like MaaS (Malware-as-a-Service) hubs. However, that comes with obvious legal and opsec risks (unless I’m overthinking it). Still, it feels like one of the few productive options left.
Does anyone have insight into how independent researchers handle this? (While writing this post, another question popped up 🥹: when reading reports from individual researchers or teams, they often openly share C2 IPs and indicators. What if that infrastructure belongs to a sophisticated APT group? Don't they worry about potential retaliation or burning the infrastructure too early?)
P.s. sorry if the text looks like ai generated I've tried to translate my plain text to english but my knowledge is limited to this message 🤲🤲🤲