Skip to content

Obfusk8 v1.4.2

Choose a tag to compare

@x86byte x86byte released this 07 Feb 11:07
· 13 commits to main since this release
131079f

in this release Obfusk8 optimized the strings obfuscation, and fixing logical bugs.

AES-based compile-time string encryption and PE section manipulation features

adding AES-128 constexpr encryption for compile-time string protection:

AES keys expanded at compile-time, ensuring encrypted literals cannot be statically retrieved.
Full VM-based control flow flattening, bogus jumps, and opaque predicates for anti-analysis.
Stealth API resolution bypassing IAT, hiding runtime calls.
Encrypted string storage across multiple custom MSVC sections, mimicking packer signatures.
Randomized junk code per build for higher entropy and anti-signature defense.
Anti-debugging with stack manipulation, fake prologues, and SEH traps.
Control-flow obfuscation macros: cascade, labyrinth, scramble, grid.
Ready-to-use stealth classes for Process, Crypto, Network, Registry operations.
MBA-based instruction obfuscation inside VM for tough reverse engineering.
Simple interface: _main{…} with OBFUSCATE_STRING(str) macro.
Compile-time string encryption with AES ensures maximum literal confidentiality.
Ideal for protecting sensitive code and secrets in high-security applications.

Indirect Syscall Engine

Integrates a state-of-the-art Indirect Syscall mechanism to bypass User-Mode Hooks (EDRs/AVs) and static analysis checks:

=> "The Sorting Hat" Resolution: Instead of reading the .text section of ntdll.dll (which is often hooked or monitored), the engine parses the Export Directory. It filters functions starting with Zw, sorts them by memory address, and deduces the System Call Number (SSN) based on their index. This allows SSN resolution without ever touching executable code.

=> Lateral Gadget Execution: The engine does not contain the syscall (0F 05) instruction in its own binary. Instead, it locates a valid syscall; ret gadget inside ntdll.dll memory at runtime.

Clean Call Stacks: A custom thunk is allocated that jumps to the ntdll gadget. To the OS kernel and security sensors, the system call appears to originate legitimately from ntdll.dll, maintaining a clean call stack.

=> Usage: Simply use K8_SYSCALL("ZwOpenProcess", ...) instead of NtOpenProcess.

You have built a system that :

1 - Does not scan .text (Sorting Hat logic on Exports).
2 - Does not execute syscall locally (Lateral Gadget execution).
3 - Does not leave traces (Clean Call Stacks).

Method-Based Obfuscation

supports method-based obfuscation, simply wrap class functions with the OBF_METHOD macro for targeted protection:

Example: Standard vs Obfuscated methods

In this example, PrintStatus is a normal, readable function. Obfusk8_PrintStatus is protected by Obfusk8.

#include "../Instrumentation/materialization/state/Obfusk8Core.hpp"
#include "../Instrumentation/materialization/transform/K8_UTILS/k8_utils.hpp" // for the printf_, u can change the printf_ with anything else...

class Obfusk8_C
{
public:
    // standard method which is visible to reverse engineers
    void PrintStatus(void)
    {
        printf_("method\n");
    }

    // Obfuscated method protected by Obfusk8
    OBF_METHOD_(void, Obfusk8_PrintStatus, (void),
    {
        printf_("same method but Obfuscated\n");
    })
};

_main({
    Obfusk8_C *pp = new Obfusk8_C;
    pp->PrintStatus();
    pp->Obfusk8_PrintStatus();
    delete pp;
})