abuse.ch founder seeks funding to sustain threat intel
After 13 years of providing free malware intelligence, abuse.ch founder seeks organizational funding to transition the one-person project into a sustainable research initiative by end of 2020.
abuse.ch, a long-running threat intelligence platform that has provided free malware data since 2007, faces sustainability challenges as its founder seeks to transition it into a formal research project. Started as a personal blog documenting malware samples, the project grew to include ZeuS Tracker (2009) and more recent crowdsourced platforms URLhaus and MalwareBazaar. The infrastructure now handles massive data volumes from the infosec community including SOCs, CSIRTs, and security vendors.
The project remains a one-person operation maintained in spare time, with infrastructure costs and big data analysis requirements becoming increasingly challenging. Despite widespread use by organizations protecting networks and customers, the founder reports difficulty securing fundamental commitments from major users. The goal is to obtain sufficient funding by end of 2020 to enable hiring additional staff, expanding infrastructure, and launching new projects while keeping all data free for commercial and non-commercial use.
The founder emphasizes uncertainty about the project's future if funding goals aren't met, noting that while there are no plans for immediate shutdown, continuing the current model for another decade is unsustainable. The appeal highlights a contrast between organizations' willingness to pay millions in ransomware demands versus supporting free threat intelligence infrastructure.
Mentioned in this report
Source reporting: https://abuse.ch/blog/moving-forward
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free