Skip to content
Launch of Kunai Sandbox for Linux Malware Analysis

Launch of Kunai Sandbox for Linux Malware Analysis

First seen 4 Oct 2026, 04:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 06:06 UTC
  • •Kunai Sandbox replaces the previous DMA service for Linux malware analysis.
  • •It supports both x86_64 and aarch64 architectures for comprehensive malware behavior analysis.
  • •The service is open-source, allowing users to run their own instances.

CIRCL has launched the Kunai Sandbox, a new malware analysis service for Linux-based malware, replacing its previous Dynamic Malware Analysis (DMA) service. This sandbox allows users to execute Linux malware samples in an isolated environment and generates detailed dynamic-analysis reports. The Kunai Sandbox supports both x86_64 and aarch64 architectures, providing insights into malware behavior and network interactions. Users can access the service via a public web interface and are encouraged to submit only authorized files. The Kunai Sandbox is open-source, with its code available on GitHub, allowing users to run their own instances. The transition from DMA to Kunai Sandbox signifies an upgrade in malware analysis capabilities for cybersecurity professionals.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-03
Kunai Sandbox launched
CIRCL introduced the Kunai Sandbox, enhancing malware analysis for Linux systems and replacing the DMA service.
Circl.Lu
2026-10-03
Kunai Project Sandbox announced
The Kunai Project Sandbox was detailed on GitHub, highlighting its features for analyzing malware samples.
github.com

More articles in this cluster (2)

Following this threat?

Track Circl in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What is the Kunai Sandbox?
The Kunai Sandbox is a new service from CIRCL for analyzing Linux-based malware in an isolated environment.
Can I run my own instance of Kunai Sandbox?
Yes, Kunai Sandbox is open-source, and users can run their own instances using the provided GitHub resources.
What types of malware can be analyzed?
The sandbox is designed specifically for Linux-based malware samples.