Launch of Kunai Sandbox for Linux Malware Analysis
Article Content
- •Kunai Sandbox replaces the previous DMA service for Linux malware analysis.
- •It supports both x86_64 and aarch64 architectures for comprehensive malware behavior analysis.
- •The service is open-source, allowing users to run their own instances.
CIRCL has launched the Kunai Sandbox, a new malware analysis service for Linux-based malware, replacing its previous Dynamic Malware Analysis (DMA) service. This sandbox allows users to execute Linux malware samples in an isolated environment and generates detailed dynamic-analysis reports. The Kunai Sandbox supports both x86_64 and aarch64 architectures, providing insights into malware behavior and network interactions. Users can access the service via a public web interface and are encouraged to submit only authorized files. The Kunai Sandbox is open-source, with its code available on GitHub, allowing users to run their own instances. The transition from DMA to Kunai Sandbox signifies an upgrade in malware analysis capabilities for cybersecurity professionals.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Circl in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What is the Kunai Sandbox?
Can I run my own instance of Kunai Sandbox?
What types of malware can be analyzed?
Continue Reading
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…