Attacks on Bytecode Interpreters Conceal Malicious Injection Activity
ID: 2dcf4ef2-d387-507a-b45a-c614a6745cac
STIX ID: report--2dcf4ef2-d387-507a-b45a-c614a6745cac
Feed Name: Dark Reading
Researchers from NTT Security and the University of Tokyo will demonstrate "Bytecode Jiu-Jitsu" at Black Hat USA: a technique that inserts or replaces interpreter bytecode in memory (demonstrated for VBScript and confirmed for Python and Lua) so malicious instructions are executed by the interpreter while evading most endpoint scanners that do not inspect in-memory bytecode. The approach leverages interpreter behavior rather than exploiting a traditional vulnerability; recommended mitigations include enforcing write protections and restricting memory writes in interpreters.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
