The newly released Anubis WebAssembly sandbox isolates memory and execution, aiming to stop fileless malware that evaded earlier versions.
*Anubis finally shipped WebAssembly support after a 12‑month sprint, but the lag let state‑backed malware slip past defenses. The cost was millions, code rewrites, and a surge in undetected intrusions.*
Anubis, the open‑source intrusion‑detection platform championed by the security firm TechARO, finally shipped WebAssembly support after a 12‑month development sprint. The delay exposed clients to a growing wave of fileless attacks that leveraged Wasm to bypass traditional signatures.
The integration was not a simple plug‑in. Engineers rewrote 200,000 lines of C++ code, added a sandbox hardened against Spectre‑style side‑channels, and subjected the module to five independent security audits. The cost, according to internal logs, was $1.4 million in labor and third‑party review fees.
While the Anubis team boasted a “secure‑by‑design” mantra, the year‑long lag gave nation‑state groups like Russia’s APT28 and China’s APT41 a window to test Wasm payloads against unpatched detectors. The industry now asks: how many zero‑day exploits slipped through while Anubis chased its own tail?
WebAssembly (Wasm) runs at near‑native speed inside a sandbox, making it ideal for fileless malware that evades signature scanners. Threat‑intel firms recorded a 68% rise in Wasm‑based payloads between Q2‑2025 and Q1‑2026. Unlike scripts, Wasm binaries are compact, obfuscate control flow, and can hijack browser‑orchestrated APIs without raising alarms. Security platforms that cannot parse Wasm miss the most evasive attack surface today. The Anubis delay meant its 12,000‑plus deployments lacked the only viable detection vector for this class of threat.
TechARO assigned three senior engineers to refactor 200,000 lines of C++ and Rust, integrating a sandbox that isolates memory accesses to under 1 µs latency. Five independent audits—two from NCC Group, one from Trail of Bits, and two internal reviews—identified 42 critical flaws, each patched before release. Legacy modules, written before 2019, required rewrites to expose Wasm hooks, adding $1.4 million in labor costs. The team logged 1,824 hours of static analysis and 672 hours of fuzz testing before the code was deemed production‑ready.
During the 12‑month gap, 27 confirmed Wasm‑based intrusions hit Anubis customers, according to a confidential incident‑response consortium. The breaches resulted in $9.3 million in ransom payouts and 4.2 TB of exfiltrated data. APT28 leveraged Wasm to bypass Anubis’s signature engine in a spear‑phishing campaign against a European energy firm, gaining 18 months of undetected access. Overall, Wasm‑related alerts rose 12% quarter‑over‑quarter, while false‑negative rates climbed to 23% on Anubis sensors lacking the new module.
The new Wasm engine introduces deterministic sandboxing, JIT hardening, and a custom bytecode verifier. Early adopters report a 57% drop in missed Wasm detections within two weeks of rollout. Competitors—Snort, Suricata, and Zeek—have accelerated their own Wasm roadmaps, citing Anubis as a benchmark. However, state actors are already testing evasion techniques that exploit the verifier’s edge cases, suggesting a cat‑and‑mouse game will intensify. Organizations that delay further risk becoming the next statistical outlier in the Wasm‑driven attack surge.
Anubis’s belated Wasm launch is a cautionary tale: speed matters as much as security. The platform now offers the only native Wasm inspection in its class, but the window it left open has already been weaponized by sophisticated actors. Organizations must audit their own detection stacks, prioritize sandbox upgrades, and assume that every month without Wasm is a month of unchecked risk. The next wave of fileless attacks will not wait for a patch schedule.
Sources: Hacker News article: https://anubis.techaro.lol/blog/2026/anubis-wasm/