Enter the WasmForge: Compiling Sliver into WebAssembly
ID: 856a1c0a-dcb1-56e5-bcf0-c3649a9f98f4
STIX ID: report--856a1c0a-dcb1-56e5-bcf0-c3649a9f98f4
Feed Name: Security Boulevard
WasmForge is a WebAssembly-based loader that compiles Go projects (and potentially .NET/NativeAOT outputs) to WASM, embeds the module into a Go binary hosting a customized Wazero runtime, and exposes ~80 host shim functions to bridge WASI gaps (sockets, Win32, macOS frameworks). The build pipeline applies numerous opsec/evasion measures — randomized WASM opcode mappings and headers, mirrored memory and pointer heuristics, COM/vtable mirroring, ghost gopclntab profiles, rotated DLL imports and signing identities — allowing standard offensive tools (Sliver, Chisel, mimikatz ports, etc.) to run on hardened Windows and macOS endpoints with reduced detection, and has been validated in lab and engagement testing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
