Skip to content

Threatray

Swiss malware code-search and binary intelligence platform, spun off from Bern University of Applied Sciences, that indexes over 100 million malware binaries to trace code-level relationships between threats.

Visit Website ↗ + Add to Compare
52/100Incremental Innovator

Overview

Threatray builds a malware code-search and binary intelligence platform that indexes more than 100 million malware binaries and applies code-similarity algorithms — rather than signature or hash matching alone — to identify relationships between known and previously unseen malware samples. The approach lets threat intelligence and incident response teams trace a new sample back to a known malware family or threat actor’s toolkit even when the code has been repacked or partially modified, a common evasion technique that defeats simpler detection methods.

The company is a 2018 spin-off from Bern University of Applied Sciences in Switzerland, co-founded by Prof. Endre Bangerter and Jonas Wagner, and has stayed close to its academic research roots, publishing methodology on large-scale malware code search rather than only marketing claims. It has raised a modest CHF 2.3 million seed round and operates with roughly 10 employees, reflecting a deep-tech, research-driven scale rather than a heavily commercialized one.

Threatray’s named commercial relationships — including a research collaboration with threat intelligence vendor Intel 471 and deployment by Swiss managed security provider InfoGuard — give it more concrete, checkable evidence of real-world use than many early-stage threat intelligence startups can point to, even though its overall customer base remains small.

Innovation Matrix Assessment

Innovation Velocity 5/10

A roughly 10-person team has built and continues to expand a code-search index now covering over 100 million malware binaries, alongside a public research partnership with Intel 471, a reasonable pace for a deep-tech academic spin-off of this size.

Operational Value 6/10

Code-similarity search across a 100M+ binary index is architecturally well-suited to catching repacked or lightly modified malware variants that hash- or signature-based detection misses, directly serving threat intel and IR team workflows.

Market Momentum 3/10

Threatray's most recent disclosed funding is a CHF 2.3M seed round from 2021, and the company remains at roughly 10 employees, indicating slow, deliberate growth rather than strong commercial momentum.

Category Disruption 6/10

Applying large-scale code-similarity search to malware attribution, rather than relying on hashes or handwritten YARA-style signatures, is a meaningfully different technical approach to a persistent detection-evasion problem.

Real-World Efficacy 5/10

A named deployment by Swiss MSSP InfoGuard and a formal research collaboration with established threat intelligence vendor Intel 471 provide concrete, checkable real-world use, though no independent benchmark of detection accuracy against competing malware analysis platforms was found.

Enduring Relevance 6/10

Malware variant proliferation and repacking to evade signature-based tools remain persistent problems for threat intelligence and IR teams, keeping code-level similarity search a relevant complementary technique.

Why CISOs Should Care

For threat intelligence and incident response teams, Threatray's code-search approach can connect a new incident to a known malware family or actor's toolkit even when the sample has been modified to evade traditional signature matching.

What Makes It Different

Threatray's core differentiation is indexing malware at the level of code structure and similarity across a 100M+ binary dataset, rather than matching hashes or known signatures, letting it surface relationships hash-based tools would miss.

The Matrix Verdict

52/100 — INCREMENTAL INNOVATOR

A technically credible, research-grounded malware intelligence platform with real named deployments, but still small-scale and modestly funded relative to more heavily backed threat intelligence competitors.

Editorial Note: Claims vs. Verified Findings

The 100 million+ indexed binaries figure is a vendor-stated platform metric that has not been independently audited. The Bern University of Applied Sciences spin-off origin, the Intel 471 research collaboration, and the InfoGuard deployment are independently reported via press releases and are treated as verified.

Sources