ScatterBrain: Unmasking the Shadow of PoisonPlug's Obfuscator
ID: 8af2a121-eddf-51cb-843d-41cc2b31c508
STIX ID: report--8af2a121-eddf-51cb-843d-41cc2b31c508
Feed Name: Google Cloud Threat Intelligence
This report presents an in-depth analysis of the ScatterBrain obfuscator—used by POISONPLUG.SHADOW/Shadowpad—detailing its protection primitives, three operational modes (Selective, Complete, Complete "headerless"), and protection components (control-flow obfuscation, instruction mutation, import protection). The authors describe recovering obfuscated samples, inferring the obfuscator's behavior, and developing a standalone static deobfuscator library; the work highlights the obfuscator's evolving nature and the challenges it poses to binary analysis and defense.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
