LummaC2: Obfuscation Through Indirect Control Flow
ID: 14d50041-396f-5d61-a5be-f5527c64826b
STIX ID: report--14d50041-396f-5d61-a5be-f5527c64826b
Feed Name: Google Cloud Threat Intelligence
This report describes a deobfuscator design for recovering original control flow and rebuilding functions from binaries obfuscated with dispatcher-style indirect jumps. It covers using Triton to determine indirect jump destinations, a DFS traversal to explore execution paths, and instruction-rewriting techniques to replace dispatcher blocks and restore original conditional/unconditional jumps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
