Threat intelligence, malware analysis, and reverse engineering.

Threat Actors

Profiles of threat actors behind notable malware campaigns and intrusions.

Financially Motivated 2025

TamperedChef

Operation behind AceLauncher and the AppSuite PDF Editor backdoor — trojanized, code-signed apps distributed via convincing malvertising.

Read profile →
Nation-State 2026

Sandworm Team

Russian GRU unit (APT44) behind the 2015 and 2016 Ukraine power grid attacks, NotPetya, and Olympic Destroyer.

Read profile →
Nation-State 2026

Xenotime

Group behind TRISIS/TRITON, the first malware built to target a safety instrumented system rather than the process it protects.

Read profile →

Malware

Technical breakdowns of notable malware families, from delivery to impact.

Infostealer 2025

AceLauncher

A fake browser productivity tool tied to TamperedChef/EvilAI — from AI-generated landing page to .NET binary teardown.

Read profile →
ICS Protocol Abuse 2026

Industroyer

The first malware framework built to speak grid-control protocols directly — used against a Kyiv transmission substation in 2016.

Read profile →
Safety System Sabotage 2026

TRISIS (TRITON)

The first malware to target a safety instrumented system directly — deployed against Triconex controllers at a Saudi petrochemical plant in 2017.

Read profile →

Resources

Curated tools, references, and reading material for security professionals.

Malware Analysis

A curated collection of resources, tools, and references for malware analysis and reverse engineering.

View on GitHub →

APT Compendium

A comprehensive reference on Advanced Persistent Threat groups, their TTPs, and associated campaigns.

View on GitHub →

Malware Compendium

A comprehensive reference on malware families, their capabilities, and how to analyze them.

View on GitHub →

YouTube Videos

In-depth walkthroughs, tutorials, and research breakdowns.

Blogs

Long-form writeups, research findings, and technical breakdowns.

Malware Analysis 2025

PE Header Fundamentals: The First Step in Malware Analysis

A practical guide to the PE file format — headers, sections, imports, exports, and detecting packed or obfuscated binaries.

Read post →
Malware Analysis 2025

Malware Analysis: A Beginner's Guide

An introduction to malware analysis — covering types of malware, static vs dynamic analysis techniques, and the tools used to dissect samples.

Read post →

About Astra

Astra covers threat intelligence and malware analysis, with a focus on reverse engineering real samples, tracking the threat actors behind them, and breaking down how these attacks actually work.

Get in Touch

astralabs.research@gmail.com

YouTube Content
Research & Blogs
Open Tools