ON THE RECORD
2026HIDDEN MALWARE REPORT: 1,085 PUBLIC REPORTS EXAMINEDPRODUCTFILE EVIDENCE MEETS AI INVESTIGATIONLEADERSHIPEMMY LINDER, CEO / MIKE WIACEK, CTO2026HIDDEN MALWARE REPORT: 1,085 PUBLIC REPORTS EXAMINED

COMPANY / CYBERSECURITY

Stairwell gives yesterday’s malware a second chance to get caught

Attackers count on defenders missing something once. Stairwell keeps the files and asks again - turning an enterprise’s digital past into a working instrument of defense.

A file arrives. A security tool examines it. Nothing sufficiently alarming happens. The file stays, or disappears, and the organization moves on. Weeks later, someone publishes a report about an attack. Suddenly, that ordinary little object would be very interesting to inspect. Provided, of course, somebody kept it.

This is the awkward interval Stairwell has chosen as its business: the distance between an event and our understanding of it. In cybersecurity, knowledge can arrive late. An attacker does not obligingly attach a note explaining which research paper will eventually expose the scheme. Defenders must make decisions before the full story exists.

THE STORY IN FOUR POINTS
  • Keep the file. Stairwell preserves collected executable evidence in a private environment.
  • Ask again. New intelligence can trigger analysis of old files.
  • Find the relatives. Variant Discovery looks beyond one exact file hash.
  • Work with the stack. Investigations feed the tools security teams already use.

The trouble with a clean bill of health

The seductive thing about a verdict is its punctuation. Benign. Case closed. Yet a detection system’s conclusion depends on what it knows at that moment. A file can remain unchanged while the evidence against it improves considerably. Treating the original decision as permanent turns an ordinary limit of knowledge into an operational blind spot.

Stairwell’s explanation of YARA at scale puts the problem in practical terms. YARA rules describe patterns inside files: strings, byte sequences and structural traits. They need actual files to inspect. A log may record an event without preserving the object that caused it. A rule written after that object has vanished has very little to say about the past.

The company’s answer is to build the file collection first. New files meet existing rules; new rules meet historical files. This changes the scheduling of a hunt. Instead of assembling evidence for each fresh advisory, a team can repeatedly interrogate the evidence it has already preserved. Yesterday becomes searchable inventory.

A SECOND LOOK, BUILT INTO THE SYSTEM
  1. 01CollectFiles and their context
  2. 02PreserveA private evidence history
  3. 03Re-examineNew intelligence, old files
Time moves forward. The next good question can travel backward. An editorial schematic of Stairwell’s file-preservation workflow.

A founder with unfinished business

Mike Wiacek had already spent years inside the security industry before starting Stairwell in 2019. He founded Google’s Threat Analysis Group and cofounded Alphabet’s Chronicle. These are useful credentials for a business asking customers to entrust it with suspicious software; more revealing is the dissatisfaction behind the new venture.

In his 2025 account of the company’s origins, Wiacek describes leaving Google because defenders needed better visibility and a stronger position against attackers. The founding argument was about giving practitioners a fuller understanding of their own environment. A company can purchase intelligence about the world and still struggle to answer a rather domestic question: did this happen here?

Mike Wiacek, Stairwell founder and CTO
Mike Wiacek, founder and CTO. His company has made a business of giving old files another appointment with the investigators. Photograph published by Stairwell.

Stairwell’s first public introduction came in 2020. In 2021 it introduced Inception, a platform for recursive threat hunting, detection and response. The name was apt for a product whose investigations could lead into further investigations. Find a suspicious object, discover related objects, then follow what those relationships reveal.

FOX went back through the alerts

The most persuasive example is a customer doing something specific. In Stairwell’s FOX Corporation case study, the broadcaster’s security team describes using the platform alongside a layered defense. News coverage and prominent sporting events create exposure; another layer of visibility was the attraction.

“Sophisticated attackers are adept at evading detection systems.”Dean Perrine, Deputy CISO, FOX

FOX became an early-access design partner and contributed feedback to feature development. Its teams used Stairwell for retrospective hunts, integrated enrichment into their ticketing workflow, and searched for variants of files that had triggered alerts during the preceding year. That last detail deserves attention. An alert already handled can become the entrance to a larger investigation.

The case study credits Stairwell with identifying threats missed by FOX’s firewall, endpoint detection and response system, and security information and event management system. This is a customer account published by the vendor. Its useful lesson is the workflow: revisit a known clue, look for its relatives, and bring the findings into the process analysts already follow.

One fingerprint is a poor family portrait

A hash is a precise identifier for a particular file. Precision is wonderful until the object changes. A modified sample may have a different hash while retaining features that connect it to the original. An investigation limited to the first identifier risks mistaking a whole collection of relatives for strangers.

Stairwell’s Variant Discovery addresses that gap. Its 2026 Hidden Malware Report examined 1,085 public threat reports published from March 2023 through June 2026, containing 19,418 malware hashes. The company reports that its variant searches expanded detection by 2.4 times, surfacing related malicious files absent from the published lists.

BEYOND THE PUBLISHED HASH LIST
Starting set
1×
With variants
2.4×
More relatives at the reunion. Stairwell’s reported detection expansion in its 2026 research dataset; normalized to a starting value of 1. This is a vendor study, not a forecast for every customer.

The distinction matters. A research result shows what happened in that collection of reports. It does not promise a matching improvement inside every enterprise. The transferable idea is narrower and sturdier: a published indicator is a starting point, and a search for related evidence can widen the inquiry.

AI gets a file to read

In May 2025, Stairwell announced Stairwell Intelligent Analysis. The launch connected generative AI with the company’s file and threat intelligence data. The appeal is easy to understand: analysts need more than a collection of labels. They need an explanation they can use.

The company’s April 2026 AI Triage deep dive describes static analysis: reading a file’s structure and logic without executing it. Outputs include a plain-English summary, maliciousness likelihood, confidence, indicators, MITRE ATT&CK mapping and recommended actions. It sits between a quick hash lookup and the fuller exercise of running a sample in a sandbox.

Static analysis has a particular attraction when malware refuses to perform under observation. But a description of what software appears capable of doing and evidence of what it actually did answer different questions. Analysts still need to interpret the result. The public trial’s terms explicitly acknowledge that language-model analysis cannot be perfectly accurate.

By October 2026, Stairwell’s website presents Backstory as an AI investigator that connects collection, detection, campaign investigation and response recommendations. The thread running from Inception to this presentation is preserved evidence. AI adds a way to interrogate and explain that evidence.

The bill, the vault and the existing desk

Building this approach took outside capital. A $4.5 million seed round preceded the $20 million Series A. On October 11, 2022, Stairwell announced a $45 million Series B led by Section 32, bringing disclosed funding to $69.5 million. Sequoia, Accel, Lux Capital and Gradient Ventures participated, alongside Eric Schmidt and Michael Ovitz. Those are financing figures, not the price a customer pays.

The commercial model is enterprise cloud software sold through sales conversations and partners. The enterprise buyer evaluates a private repository and continuing investigation workflow. Someone merely curious can take the virtual tour or try the public file-analysis tool. The distinction between those routes matters: the public trial terms prohibit sensitive or confidential submissions and grant Stairwell rights to use submitted files for business-related purposes.

For an existing security operation, the practical question is where the output lands. Stairwell’s Google Security Operations integration, generally available in October 2025, sends case indicators for enrichment and returns analysis into the case timeline. Verdicts, rule matches and variant context can meet the analyst at the desk they already occupy. Less switching between tools is a modest claim with an obvious daily value.

Preserve first. Become clever later.

A security team can copy the governing habit without copying the entire company: retain relevant evidence before its importance is obvious, connect detections to file context, and revisit historical material when knowledge improves. A new advisory should provoke a question about the organization’s past as well as a rule for its future.

This requires collection coverage. A repository cannot inspect an executable it never received, and a failed search cannot establish safety outside the evidence searched. Review matters too: automated analysis supplies judgments that someone must weigh before acting. The company’s technical design makes a second look possible; the organization must decide what that look justifies.

Stairwell’s own research has room for an unexpectedly visual flourish. Its Hilbert-curve visualizations map file bytes into colored grids, exposing patterns and anomalies. Binary inspection acquires something of the art gallery. The object remains evidence, but a different view can make a detail easier to notice.

In July 2025, Emmy Linder became CEO and Wiacek moved to CTO. The company continues to build around a question whose simplicity hides its difficulty: what have we missed? Stairwell’s answer begins by ensuring that, when somebody finally knows where to look, there is still something there to examine.

Open the next door

Explore the platform and interactive product tour, watch the Intelligent Analysis demo, or browse Stairwell’s YouTube channel. Follow its LinkedIn, X and Facebook profiles, inspect the public GitHub repositories, and read the technical blog or leadership announcement.