New Zealand’s Malware Free Networks (MFN) initiative is intended to help organisations identify and disrupt malicious infrastructure. But recent observations from a New Zealand cybersecurity practitioner raise serious questions about the timeliness, relevance and practical value of the indicators being distributed through the service.
The concerns began with something relatively straightforward: three compromised New Zealand business websites hosting phishing pages.
All three websites were running either Joomla or WordPress, had been built by the same web design company and were using the same theme on the same host. The compromised sites were reported to New Zealand’s National Cyber Security Centre (NCSC), with the expectation that the indicators could be rapidly assessed and, where appropriate, distributed through the MFN feeds.
Instead, the experience became an example of the gap that can exist between threat intelligence in theory and threat intelligence in practice.
Three compromised New Zealand websites
The initial discovery involved three legitimate New Zealand business websites that had apparently been compromised and were being used to host phishing content.
The sites were not purpose-built malicious infrastructure. They were legitimate business websites that had been compromised and repurposed.
That distinction matters.
A phishing page hosted on a legitimate New Zealand business domain can provide attackers with an additional layer of credibility. Victims may be considerably more likely to trust a link pointing to a genuine business website than an obviously suspicious newly registered domain.
The sites were reported to the NCSC, and an attempt was also made by the inital discoverer to contact the web design company responsible for the websites.
Almost 24 hours later, the NCSC requested additional information, despite the reporter believing the original submission contained enough information to identify and investigate the compromised sites.
For a cybersecurity practitioner working in Cyber Threat Intelligence, that delay is significant.
An indicator of compromise is a perishable commodity. The value of an IOC can decline rapidly once infrastructure is remediated, taken offline, blocked by other security providers or simply abandoned by an attacker.
Seven days later, the sites were still not blocked
Six days after the original report, additional compromised New Zealand websites were identified. These had also been submitted by other New Zealand users to online malware-analysis services.
The new information was passed to the NCSC.
There was initially no response.
After following up, a response arrived the following day — approximately seven days after the original report.
The NCSC’s assessment was that the affected websites were “not wholly malicious” and therefore did not meet the threshold for blocking through MFN.
There is an important distinction here between a website being malicious by design and a legitimate website being compromised and used to facilitate malicious activity.
At the time of the response, the reported websites were still hosting phishing pages.
That raises an obvious question: if a legitimate New Zealand business website has been compromised and is actively hosting phishing content, what level of malicious activity is required before that infrastructure is considered suitable for disruption?
For organisations operating phishing-disruption or threat-intelligence programmes, speed is critical. A phishing campaign can have a useful operational lifetime measured in hours, not days.
A stark contrast with the old CERT NZ model
The experience is particularly frustrating when compared with the previous CERT NZ phishing-disruption model.
Before CERT NZ was absorbed into the NCSC, phishing indicators submitted to CERT NZ could reportedly make their way into the relevant disruption feeds in a matter of hours.
The contrast described here is stark:
Then: approximately four hours for reported phishing indicators to be pushed back into the ecosystem.
Now: approximately seven days to receive a determination that the infrastructure did not meet the MFN blocking threshold.
That difference is not merely administrative.
For defenders attempting to use threat intelligence operationally, the difference between four hours and seven days can be the difference between preventing an attack and documenting one after the fact.
What is actually in the MFN feeds?
The concerns extend beyond the handling of compromised websites.
Analysis of the MFN indicators being consumed by the researcher also raises questions about the practical value of the IP, URL and domain feeds.
These observations are based on one organisation’s telemetry and should therefore not be interpreted as a comprehensive statistical assessment of MFN. However, they are sufficiently unusual to warrant wider discussion and independent validation.
MFN IP indicators
At the time of analysis, 1,362 IP addresses had been ingested from the MFN IP feed during the month.
Of those, 558 — approximately 41% — had also appeared in the previous month’s MFN feed.
The researcher compared the indicators against NZ business firewall telemetry containing thousands of observed scanning and probing IP addresses.
Of 4,765 probing IP addresses observed so far during the month, only six correlated with addresses appearing in the MFN IP feed.
That represents a very small overlap between the MFN IP indicators and the malicious scanning activity being observed directly at the perimeter.
There is also a question about why particular IP addresses are being included.
Repeated searches through public threat-intelligence sources and security forums have often failed to establish a clear explanation for their inclusion in the MFN feed.
The indicators may have legitimate intelligence value that is not publicly documented. However, from the perspective of a consumer trying to validate and operationalise the data, unexplained indicators are difficult to assess.
The problem becomes even more pronounced when defenders are seeing constant malicious activity from other IP addresses that are not represented. One Chinese IP address is continually observed actively scanning fortigate firewalls, it is known in OSINT circles to attempt brute force dictionary attacks aswell yet doesnt feature in the MFN feeds and continues to constantly probe NZ fortigate devices.
What about CISA?
The same question can be asked when comparing MFN with publicly available intelligence from other national cybersecurity organisations.
For example, a CISA advisory concerning Gunra ransomware published in August listed 17 IP addresses. None of those IP addresses appeared in the MFN IP feed examined.
That does not necessarily mean the feeds should contain identical indicators. Different organisations have different collection sources, visibility and inclusion criteria.
But it does reinforce a broader question:
What intelligence is the NZ NCSC actually collecting, and how does it determine which indicators are valuable enough to distribute?
The URL feed: overwhelmingly Mozi-related
The MFN URL feed presents another interesting picture.
More than 95% of the URLs examined were readily identifiable as Mozi-related because “mozi” appeared directly within the URL.
Mozi is a malware family associated primarily with IoT botnet activity and has been documented for years.
In some cases, the IP address or domain associated with an MFN URL also appears in the corresponding MFN IP or domain feed.
In other cases, the IP or domain from the URL is left out of the other MFN feeds for an unknown reason.
Again, there may be intelligence or collection context that is not visible to feed consumers.
But that lack of context makes independent validation difficult.
One particularly unusual example this month involved:
update.rawupdater[.]cf
The domain has historical references dating back to 2023, including associations with the Mirai botnet. The domain was reportedly renewed by the main ISP in the Central African Republic on 4 August 2026.
However, searches conducted during the investigation did not reveal evidence of current malicious activity associated with the domain for years.
Years of tracking and recording sightings of all the URLs contained within the MFN feed has also reportedly failed to produce a single observed hit. Not a single one. Zero.
That raises another fundamental question about the operational purpose of the feed.
If indicators are never observed in the environment being monitored, are they providing meaningful defensive value? The value of the CertNZ phishing-disruption feed has completely gone.
The domain feed
The MFN domain feed showed a similar pattern.
During the month, 83 domains had been ingested.
Thirty-one of those domains — approximately 37% — had also appeared in the previous month’s feed.
Only one domain had produced any observed sightings in the monitored environment.
Perhaps unsurprisingly, open-source intelligence from ThreatFox associated that one domain with the Mirai botnet.
Again, this does not prove that the remaining indicators are inaccurate or useless.
It does, however, raise a legitimate question about how much of the feed represents genuinely useful, current threat intelligence versus historical or low-value infrastructure.
Is MFN primarily tracking old botnet infrastructure?
Taken together, the observations create an uncomfortable hypothesis.
The researcher believes the MFN feeds increasingly resemble collections of historical and current Mozi and Mirai-related indicators rather than a broad, high-value source of New Zealand-relevant malicious infrastructure.
That conclusion cannot be established from this data alone.
The NCSC may have additional intelligence sources, collection methods and validation criteria that are not publicly disclosed. There may also be legitimate operational reasons why certain indicators appear in the feeds.
But secrecy creates a difficult trade-off.
Threat intelligence providers understandably cannot disclose every collection source or investigative technique.
At the same time, consumers need enough information to determine whether an intelligence feed is actually improving their defensive capability.
Without that transparency, organisations are left evaluating feeds largely through their own telemetry.
And the telemetry described here is not encouraging.
The cost of “free” threat intelligence
There is another issue that deserves attention.
Despite the name, MFN threat intelligence is not free for New Zealand businesses to consume operationally.
Access to the feeds is generally obtained through participating managed security service providers, and organisations can end up paying thousands of dollars per year for services that incorporate the intelligence.
There is also an operational cost associated with providing sightings back to the ecosystem.
That creates an interesting feedback loop.
If a feed contains indicators that repeatedly generate firewall hits against closed ports (i.e. botnets crashed against closed telnet ports), those hits can become “sightings”.
But a firewall logging traffic to a closed port does not necessarily mean an attacker successfully interacted with the infrastructure.
A ‘dumb’ bot scanning TCP/23 across the internet and receiving a dropped packet is very different from an attacker successfully exploiting a vulnerable service.
For threat intelligence to be useful, defenders need to distinguish between:
- attempted scanning;
- opportunistic internet background noise;
- exploitation attempts;
- successful compromise;
- repeat offenders;
- command-and-control traffic;
- confirmed malicious infrastructure; and
- infrastructure that is no longer active.
Simply counting sightings can obscure those differences.
New Zealand could potentially build something better
There is a potentially much larger opportunity here.
New Zealand has government agencies, telecommunications providers, security operations centres, ISPs and large enterprises collectively observing enormous quantities of malicious internet traffic every day.
Imagine if appropriately governed and privacy-preserving telemetry from several larger government departments could be aggregated, correlated and turned into a national threat-intelligence capability, distributing threat intelligence within hours of sightings.
Rather than relying heavily on indicators that may already be weeks, months or years old, such a system could correlate and identify:
- active scanning infrastructure;
- newly observed malicious IP addresses;
- phishing infrastructure;
- compromised legitimate websites;
- command-and-control infrastructure;
- ransomware infrastructure;
- exploitation campaigns targeting New Zealand organisations;
- emerging attack infrastructure; and
- indicators repeatedly observed across multiple New Zealand networks.
The resulting intelligence could potentially be distributed rapidly to New Zealand businesses.
That would provide something that defenders actually need:
fresh, locally relevant, operational threat intelligence.
The objective should not simply be to create a larger IOC list.
It should be to create a better IOC list.
Threat intelligence has a shelf life
One of the most important lessons from this experience is that threat intelligence cannot be judged solely by how many indicators a feed contains.
A feed containing tens of thousands of indicators may be less useful than a feed containing a few hundred highly accurate, recently observed indicators.
Timeliness matters.
Context matters. If a security analyst can provide details to their Board about whom is hitting their firewall, then this could unlock funding to improve security controls.
Accuracy matters.
Local relevance matters.
And, perhaps most importantly, defenders need to know whether the intelligence actually changes their ability to detect or prevent attacks.
An IP address added to a feed seven days after an incident may have very little operational value.
A compromised New Zealand business website hosting an active phishing page is different.
That indicator may be immediately useful to banks, email providers, security vendors, ISPs and organisations protecting their customers.
The window for disruption can be extremely short.
A call for transparency and measurement
The MFN programme should not be judged solely on its intentions.
It should be judged on outcomes.
How many indicators are currently active?
How quickly are reported indicators assessed?
What percentage of indicators remain malicious after 24 hours, seven days or 30 days?
How many indicators produce meaningful sightings?
How many result in confirmed compromises or malicious connections?
How much of the feed consists of historical indicators?
How much is newly observed?
How much is specifically relevant to New Zealand?
And perhaps most importantly:
How many threats has MFN actually helped New Zealand organisations prevent or disrupt?
Those are reasonable questions for organisations paying for access to threat intelligence to ask.
Is it time to rethink MFN?
The experience described here ultimately led to a difficult decision: reconsider whether the MFN feeds belong in the defensive toolkit at all.
That is not a conclusion that should be reached lightly.
Threat intelligence is difficult. No feed will detect everything (but ideally it would detect something), and no IOC source will perfectly overlap with the traffic seen by every organisation.
But when defenders repeatedly observe significant malicious activity that does not appear in a national feed, while simultaneously receiving indicators that generate little or no observable activity, it is reasonable to question the return on investment.
The answer isnt to abandon MFN.
It is instead to improve it.
New Zealand has the opportunity to build a world-class national cyber-threat intelligence capability. Doing so would require greater emphasis on speed, current activity, local telemetry, validation, measurable outcomes and actionable intelligence.
The alternative is an increasingly large list of indicators that looks impressive on paper but provides little defensive value in the environments where it matters.
For a cyber threat intelligence practitioner, that is the ultimate test of any IOC feed:
Does it help me stop something?
If the answer is increasingly “no”, it may be time to ask how do I do something better.