De-obfuscating ALCATRAZ
ID: be9b8827-f238-5cd1-b755-e3c1acb34e1e
STIX ID: report--be9b8827-f238-5cd1-b755-e3c1acb34e1e
Feed Name: Elastic Security Labs
Threat Score
Elastic Security Labs analyzed DOUBLELOADER, a backdoor deployed alongside the RHADAMANTHYS infostealer, and documented how the open-source obfuscator ALCATRAZ hinders analysis through techniques like entrypoint obfuscation, anti-disassembly, instruction mutation, constant/LEA unfolding, and control-flow flattening; the report includes remediation approaches (IDA Python scripts, D810 plugin), YARA rules, and a SHA256 observable for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
