Enriched URL Reports: VirusTotal URL Scanning 2.0
IntroductionIn today's fast-moving cybersecurity landscape, threat analysts must move beyond basic, binary reputation scores to successfully defend against modern, highly adaptive web threats....
View ArticleCrowdsourced AI += Knostic
Weāre adding a new specialist to VirusTotalās Crowdsourced AI lineup: Knostic's AgentMesh Agentic Security Supply Chain Reputation Engine. We are partnering with them to analyze Visual Studio Code...
View ArticleVirusTotal Inside the Agent Loop
At VirusTotal, we are closely following how AI agents are evolving and how we can be useful in that space. Part of that is analysis: the new generation of AI-native artifacts (skills, plugins, IDE...
View ArticleFrom Automation to Infection (Part II): Reverse Shells, Semantic Worms, and...
In part one, we showed how OpenClaw skills are rapidly becoming a supply-chain delivery channel: third-party "automation" that runs with real system access. This second installment expands the taxonomy...
View ArticleFrom Automation to Infection: How OpenClaw AI Agent Skills Are Being Weaponized
The fastest-growing personal AI agent ecosystem just became a new delivery channel for malware. Over the last few days, VirusTotal has detected hundreds of OpenClaw skills that are actively malicious....
View ArticleNew Infostealer Campaign Targets Users via Spoofed Software Installers
IntroductionAs part of our commitment to sharing interesting hunts, we are launching these 'Flash Hunting Findings' to highlight active threats. Our latest investigation tracks an operation active...
View ArticleIntroducing Saved Searches in Google Threat Intelligence (GTI) and VirusTotal...
We are excited to announce the launch of Saved Searches in Google Threat Intelligence (GTI) and VirusTotal (VT), a powerful new feature designed to streamline your threat hunting workflows and foster...
View ArticleVTPRACTITIONERS{ACRONIS}: Tracking FileFix, Shadow Vector, and SideWinder
Introduction We have recently started a new blog series called #VTPRACTITIONERS. This series aims to share with the community what other practitioners are able to research using VirusTotal from a...
View ArticleReversing at Scale: AI-Powered Malware Detection for Appleās Binaries
TL;DR: We ran our new AI-based Mach-O analysis pipeline in production, no metadata, no prior detections, just raw Apple binaries. On Oct 18, 2025, out of 9,981 first-seen samples, VT Code Insight...
View ArticleNovember is the Month of Searches: Explore, Learn, and Share with...
This November, weāre celebrating the power of VirusTotal Enterprise search! All VirusTotal customers will enjoy uncapped searches through the GUIā no quota consumption for the entire month so long as...
View ArticleHugging Face and VirusTotal: Building Trust in AI Models
Weāre happy to announce a collaboration with Hugging Face, an open platform that fosters collaboration and transparency in AI, to make security insights more accessible to the community. VirusTotalās...
View ArticleVTPRACTITIONERS{SEQRITE}: Tracking UNG0002, Silent Lynx and DragonClone
Introduction One of the best parts of being at VirusTotal (VT) is seeing all the amazing ways our community uses our tools to hunt down threats. We love hearing about your successes, and we think the...
View ArticleSimpler Access for a Stronger VirusTotal
VirusTotal (VT) was founded on a simple principle: we are all stronger when we work together. Every file shared, every engine integrated, and every rule contributed strengthens our collective defense...
View ArticleCrowdsourced AI += Exodia Labs
Weāre adding a new specialist to VirusTotalās Crowdsourced AI lineup: Exodia Labs, with an AI engine focused on analyzing Chrome extension (.CRX) files. This complements our existing Code Insight and...
View ArticleAdvanced Threat Hunting: Automating Large-Scale Operations with LLMs
Last week, we were fortunate enough to attend the fantastic LABScon conference, organized by the SentinelOne Labs team. While there, we presented a workshop titled 'Advanced Threat Hunting: Automating...
View ArticleSupercharging Your Threat Hunts: Join VirusTotal at Labscon for a Workshop on...
We are excited to announce that our colleague Joseliyo SƔnchez, will be at Labscon to present our workshop: Advanced Threat Hunting: Automating Large-Scale Operations with LLMs. This workshop is a...
View ArticleUncovering a Colombian Malware Campaign with AI Code Analysis
VirusTotal Code Insight keeps adding new file formats. This time, weāre looking at two vector-based formats from very different eras: SWF and SVG. Curiously, right after we rolled out this update in...
View ArticleIntegrating Code Insight into Reverse Engineering Workflows
More than two years have passed since we announced the launch of Code Insight at RSA 2023. From that time on, we have been applying this technology in different scenarios, expanding its use in new file...
View ArticleApplying AI Analysis to PDF Threats
In our previous post we extended VirusTotal Code Insights to browser extensions and supply-chain artifacts. A key finding from that analysis was how our AI could apply contextual knowledge to its...
View ArticleCode Insight Expands to Uncover Risks Across the Software Supply Chain
When we launched Code Insight, we started by analyzing PowerShell scripts. Since then, we have been continuously expanding its capabilities to cover more file types. Today, we announce that Code...
View Article