A novel lightweight binary-level malware hybrid obfuscation against black-box anti-malware engines

Yinhao Xiao, Chih-Chung Liu, Fengting Mo, Liang Qin · High-Confidence Computing · 2025

Code obfuscation is a critical technique used by hackers to disguise malware, enabling it to evade detection by anti-malware engines. However, current obfuscation techniques often present practical challenges in deployment, or remain detectable by black-box analysis due to inherent weaknesses. This paper presents a lightweight hybrid obfuscation method, designed to circumvent these limitations without incurring the overhead of machine learning training. Our method leverages a composite strategy, combining atomic obfuscation techniques, to transform malware into a structurally similar benign counterpart, preserving its malicious functionality. Our evaluation demonstrates a substantial decrease in average detection rates, from 75.82% to 45.01%, highlighting the effectiveness of our approach.

Read the paper · More papers on PaperTik