HomeCustomer Success Story
Safeguarding 200M Users: How ChongLuaDao Scales Threat Validation with ANY.RUN
HomeCustomer Success Story
Safeguarding 200M Users: How ChongLuaDao Scales Threat Validation with ANY.RUN

ChongLuaDao protects over 200 million users from cybercrime, having detected more than 1.4 million malicious websites since 2020. Rapid processing of community reports is essential to their operations.

In our recent conversation, ChongLuaDao co-founder Hieu Ngo told us how ANY.RUN plays an integral role in the project’s infrastructure, helping it power thousands of safety checks to stop cyber threats before they reach potential victims.

A Community-Driven Mission: Small Team, Global Impact

ChongLuaDao team. Photo: Chongluadao.vn Facebook page

Based in Ho Chi Minh City, Vietnam, ChongLuaDao is a non-profit, community-driven cybersecurity initiative with a singular mission: to make online safety free, practical, and accessible for everyone.

“Our mission is to make online safety free, practical, and accessible by helping people verify suspicious websites, report scams, and block dangerous links before victims are harmed.”

The organization operates with a lean but highly efficient structure:

  • A Small Core Team: A specialized group of security analysts, engineers, and investigators who manage the project’s strategy and technical infrastructure.
  • Global Volunteer Power: A massive community of more than 200 volunteer moderators and cybersecurity experts who assist in reviewing and validating user-submitted scam reports.
  • Enterprise-Scale Ecosystem: Despite its non-profit status, the project’s impact is massive, serving over one million daily queries via its threat intelligence API and maintaining strategic partnerships with global leaders like APWG and PhishTank.

Through this unique blend of human expertise and advanced technology, ChongLuaDao has turned a local initiative into a critical node of the global threat intelligence network.

The Challenge: Scaling Analysis for the Constantly Changing Scam Infrastructure

For ChongLuaDao, the primary operational bottleneck was speed. The landscape of modern cybercrime in Vietnam is dominated by short-lived infrastructure: scam domains, phishing pages, and malicious APKs often appear and disappear within hours. Relying on manual review alone became impossible as the volume of daily suspicious submissions began to outpace the team’s capacity.

This massive influx of data created heavy pressure on the analyst team. Without the ability to perform fast dynamic analysis, validating a single suspicious file or URL could take too long. These delays had real-world consequences, leading to slower response times in blocking threats, warning potential victims, and sharing intelligence with global partners.

“Scam domains, phishing pages, fake investment sites, malicious APKs, and credential theft pages appear and disappear very quickly, so manual review alone could not keep up with the volume or urgency”

The challenge was further intensified by the organization’s status as a non-profit with limited staff, budget, and time. To protect millions of users effectively, ChongLuaDao needed an enterprise-grade solution that could drastically reduce analyst workload and provide the high-fidelity evidence required to make confident, life-saving blocking decisions in real time.

ANY.RUN Integration: Moving Beyond Static Analysis to Unmask “Smart” Phishing in Real Time

ChongLuaDao integrated ANY.RUN to overcome the technical limitations of static analysis when facing sophisticated, evasive threats. The team selected the solution based on its ability to provide real-time interaction within secure cloud-based VMs, a capability essential for analyzing modern scam infrastructure.

“From a leadership perspective, ANY.RUN helps ChongLuaDao scale our mission.”

ANY.RUN’s Interactive Sandbox delivered instant value to ChongLuaDao, offering several operational advantages:

  • Detection of Evasive and Multi-Stage Threats: Many phishing campaigns are multi-stage and depend on specific user interactions like clicking. ANY.RUN’s interactive nature allows analysts to simulate user behavior, exposing malicious flows that remain dormant and undetected in passive sandboxes.
  • High-Fidelity Verdicts and Reduced False Alarms: By providing full visibility into the entire behavior chain rather than relying on static indicators, the sandbox improves analyst confidence. This clarity is critical for distinguishing sophisticated phishing kits from legitimate but abused infrastructure, ensuring that blocking decisions are accurate.
  • Operational Efficiency for Resource-Constrained Teams: As a non-profit managing 200 million protected users with a lean staff, ChongLuaDao requires solutions that reduce manual workload. ANY.RUN acts as a force multiplier, transforming what used to be hours of manual forensic checking into minutes of interactive validation.

By prioritizing interactive visibility, ChongLuaDao has moved from simply flagging suspicious links to confirming and neutralizing complex threats in a single workflow.

Close visibility gaps that delay investigations and increase exposure.
Give your SOC the evidence to act faster.

Reduce Security Exposure

Triaging Threats in Minutes Instead of Hours

By integrating ANY.RUN, the organization successfully transitioned from time-intensive manual forensics to a streamlined interactive triage process.

The efficiency allows a lean core team to handle enterprise-level volumes of data, accelerating the time-to-block for confirmed threats and significantly increasing daily analyst throughput.

“For complex cases, ANY.RUN helped reduce analysis from hours of manual checking to minutes of interactive validation.”

Exposing Multi-Stage Scams Through Real-Time Human-in-the-Loop Interaction

Sophisticated cybercrime campaigns in Vietnam, such as “Không Một Mình,” often utilize geo-fencing or multi-stage execution that remains dormant in passive sandboxes. These threats require specific user actions to trigger their malicious payloads.

Using ANY.RUN’s interactive environment, analysts can click through phishing flows, scroll, and enter data in real time to observe the threat’s actual behavior. This “human-in-the-loop” capability allows the team to unmask malicious flows that automated systems miss, ensuring that complex, interaction-dependent scams are identified and neutralized before they reach victims.

🚀 Key ChongLuaDao Metrics Improved with ANY.RUN
  • Time-to-Verdict: For complex cases, the analysis window was compressed from hours of manual forensic checking to just minutes of interactive validation.
  • Time-to-Block: The speed of neutralizing threats increased due to the immediate extraction of network indicators, domains, and IPs directly from the sandbox.
  • Daily Analyst Throughput: The number of reports analysts and volunteer moderators can process per day has significantly increased, allowing the team to keep pace with the high volume of user submissions.

Reaching Confident Verdicts with Full Visibility into Malicious Behavior

Maintaining a blocklist for 200 million users requires accurate decisions to avoid disrupting legitimate services. ANY.RUN helps ChongLuaDao achieve this by providing complete visibility into the behavioral chain, including process trees, network activity, and file system changes.

The forensic depth allows analysts to definitively distinguish phishing kits from false alarms or legitimate but abused infrastructure.

“ANY.RUN improves confidence because analysts can see the full behavior chain instead of relying only on static indicators.”

By moving from static indicators to observed behavioral proof, ChongLuaDao has increased the reliability of its intelligence and reduced the risk of false positives.

Providing Actionable Intelligence for Law Enforcement and Global Takedown Partners

ChongLuaDao serves as a critical intelligence node for partners like INTERPOL, UNODC, and global hosting providers. ANY.RUN facilitates this cooperation by generating forensic-grade reports that include process graphs, screenshots, and detailed network logs.

“ANY.RUN makes our reports more actionable because partners can see not only a suspicious link, but also the observed malicious behavior behind it.”

Complete intelligence packages make the organization’s findings immediately actionable for partners, as they provide visual and technical proof of malicious intent rather than just a suspicious URL. The evidence-based approach directly accelerates the takedown of malicious infrastructure and strengthens global efforts to dismantle cybercrime networks.

Reduce delays between threat confirmation and containment.
Give responders the evidence to act faster.

Accelerate Incident Response

Conclusion

The ChongLuaDao case demonstrates how a lean, community-driven non-profit can successfully defend 200 million users by augmenting human expertise with professional-grade interactive analysis. By integrating ANY.RUN, the organization has effectively addressed the challenge of scam infrastructure, transforming what was once a manual bottleneck into a high-speed, evidence-based validation workflow.

We would like to thank the ChongLuaDao leadership and their community of 200+ volunteer experts for allowing us an inside look at their security operations. Their commitment to making online safety free and accessible is an inspiration, and we are proud to support their mission to build a safer digital environment for millions of users globally.

About ANY.RUN

ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions, helps SOC teams, MSSPs, and enterprises investigate threats faster and make more confident security decisions.

With its cloud-based Interactive Sandbox, security teams can safely analyze suspicious files, links, and emails in real time, observe malicious behavior, and receive clear evidence for response without maintaining complex in-house infrastructure.

ANY.RUN’s Threat Intelligence solutions also help organizations uncover threat context, enrich security workflows, and improve visibility into emerging risks. Together, these capabilities support faster triage, stronger incident prevention, and more efficient security operations at scale.

Scale your SOC with faster threat validation →

What do you think about this post?

2 answers

  • Awful
  • Average
  • Great

No votes so far! Be the first to rate this post.

0 comments