logo

De-obfuscating ALCATRAZ

ID: be9b8827-f238-5cd1-b755-e3c1acb34e1e

STIX ID: report--be9b8827-f238-5cd1-b755-e3c1acb34e1e

Feed Name: Elastic Security Labs

Threat Score
70/100

Date Published: 2025-05-23

Date Updated: 2026-04-27

...
...

Elastic Security Labs analyzed DOUBLELOADER, a backdoor deployed alongside the RHADAMANTHYS infostealer, and documented how the open-source obfuscator ALCATRAZ hinders analysis through techniques like entrypoint obfuscation, anti-disassembly, instruction mutation, constant/LEA unfolding, and control-flow flattening; the report includes remediation approaches (IDA Python scripts, D810 plugin), YARA rules, and a SHA256 observable for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.