logo

Introducing Nimfilt: A reverse-engineering tool for Nim-compiled binaries

ID: 58561a84-0315-5682-92a7-c1ac5d09a1b7

STIX ID: report--58561a84-0315-5682-92a7-c1ac5d09a1b7

Feed Name: WeLiveSecurity (ESET Research)

Date Published: 2024-05-23

Date Updated: 2026-05-01

...
...

ESET presents Nimfilt, a Python/IDA plugin that accelerates reverse engineering of Nim-compiled binaries by detecting Nim-specific artifacts, demangling function and package names (often revealing developer paths), organizing functions by package/path, and applying C-style structs to Nim strings; it includes heuristics and YARA rules to identify Nim-built PE/ELF files and is available on ESET’s GitHub, with context noting increased Nim adoption by threat actors such as Sednit and Mustang Panda.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.