Nostr'a Katılın
2026-06-24 10:23:35 UTC

Joxean Koret (@matalaz) on Nostr: This malware is pretty cool, it took me a while to get to the 4th obfuscation layer ...

This malware is pretty cool, it took me a while to get to the 4th obfuscation layer myself in IDA even when using a deobfuscation plugin myself, mixes its own obfuscated code deep in legitimate "goodware" code, uses lots of MBAs, has anti-VM tricks. High quality malware.

https://www.elastic.co/security-labs/oxloader-malware-loader-infostealer

#malware #ida #reversing #reverseengineering