Skip to main content

News, blogs, events...

Malware analysis reports

Reports and IoCs from the NCSC Malware Team.
iStock.com/sasha85ru

NCSC malware analysis reports (MARs) help network defenders understand selected malware threats in more technical depth, and provide indicators and TTPs to support threat hunting or modelling.

The reports focus on the technical detail features, components and structure of malware samples. We may also include analyst commentary to highlight notable techniques or approaches, but because of the risks around malware reuse and misinformation campaigns, MARs avoid statements on attribution or use by adversaries.

Sometimes reports may accompany wider NCSC advisories, which may explore adversaries and attribution.

While the NCSC makes every effort to assure the quality and accuracy of indicators and signatures, we remind you to use at your own risk and carry out your own validation before deploying them.

Content published in this section including reports, detection rules and STIX are licensed under the terms of the Open Government Licence v3.0 except where otherwise stated. To view this licence, visit nationalarchives.gov.uk/doc/open-government-licence/version/3. Where we have identified any third party copyright information you will need to obtain permission from the copyright holders concerned.


























Mitigating malware and ransomware attacks

How to defend organisations against malware or ransomware attacks

View guidance on mitigating malware and ransomware