Skip to content
Data Breach

ANY.RUN Sandbox Now Analyzes Complex Linux Malware For SOC & DFIR Teams

The ANY.RUN sandbox has recently undergone an update to include support for Linux, strengthening its capacity to offer a safe and isolated atmosphere for examining malware and conducting threat analysis. The latest feature introduced will facilitate security analysts to scrutinize and replicate male...

· Jul 23, 2025 · 4 min read · 👁 2 views
ANY.RUN Sandbox Now Analyzes Complex Linux Malware For SOC & DFIR Teams

The latest feature introduced will facilitate security analysts to scrutinize and replicate malevolent actions in Linux-oriented systems, providing a more extensive and potent threat perception and response.

Linux is widely used in organizational IT infrastructures, resulting in many files that need to be analyzed on these systems.

Researchers at IBM have noticed an increase in Linux malware. In 2020, the number of malware families related to Linux increased by 40%.

google

Compromising Linux-based cloud computing platforms could allow attackers access to massive resources, making the OS an appealing target.

Document

Try ANY.RUN Yourself with a 14-day Free Trial

How to Create a New Task in Linux

You can select Linux as your operating System from the drop-down menu when creating a new task.

Image

The Ubuntu logo identifies the Linux samples to help with navigation. This makes it easy to differentiate between Windows and Linux-based tasks in the team’s homepage and sidebar quick menu.

Enhancing Linux Malware Analysis with ANY.RUN’s

The platform can help analysts quickly identify undetected threats using interactive analysis, even in the case of zero-day vulnerabilities, while using fewer resources. This makes it ideal for training entry-level analysts and reverse engineers.

Upon task completion, concise reports are generated that provide access to all relevant data and IOCs, making additional investigation or incident response easier.

The platform also features an MITRE Matrix report that helps identify the kind of threat or family based on suspicious behaviors recorded in the Linux sandbox task. This feature is handy for quickly aligning suspicious behaviors with TTPs.

Advantages of using ANY.RUN to analyze Linux malware

Linux-based operating systems are inherently more secure than Windows. However, many malware families can still exploit vulnerabilities in Linux, which are complex and difficult to identify.

Image

Breaching a Linux-based system can provide access to a wealth of resources, so Linux users need to be aware of the growing threats to their devices.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Recommended for you