logo

Attacks on Bytecode Interpreters Conceal Malicious Injection Activity

ID: 2dcf4ef2-d387-507a-b45a-c614a6745cac

STIX ID: report--2dcf4ef2-d387-507a-b45a-c614a6745cac

Feed Name: Dark Reading

Threat Score
50/100

Date Published: 2024-08-01

Date Updated: 2026-04-21

Author: Robert Lemos, Contributing Writer

...
...

Researchers from NTT Security and the University of Tokyo will demonstrate "Bytecode Jiu-Jitsu" at Black Hat USA: a technique that inserts or replaces interpreter bytecode in memory (demonstrated for VBScript and confirmed for Python and Lua) so malicious instructions are executed by the interpreter while evading most endpoint scanners that do not inspect in-memory bytecode. The approach leverages interpreter behavior rather than exploiting a traditional vulnerability; recommended mitigations include enforcing write protections and restricting memory writes in interpreters.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.