APT10__2019__Defeating_Compiler-Level_Obfuscations_Used_in_APT10_Malware.pdf
ID: 5ef6f676-af8f-4e9f-af46-df25a6f380fe
STIX ID: report--5ef6f676-af8f-4e9f-af46-df25a6f380fe
Threat Score
75/100
Uploaded: 2026-08-07
Published Date: 2019-03-12
Last Modified Date: 2019-03-12
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Carbon Black TAU analyzed ANEL (UpperCut) samples linked to APT10 that employ compiler-level obfuscations (opaque predicates and control-flow flattening). They extended the HexRaysDeob IDA plugin with new pattern matches, data-flow tracking, multi-maturity-level handling, multi-dispatcher support, and other heuristics to recover original code; the modified tool deobfuscated ~89% of functions in a tested ANEL 5.4.1 sample (SHA256: 3d2b3c9f50ed36bef90139e6dd250f140c373664984b97a97a5a70333387d18d). The report details the algorithms, examples of before/after decompilation, known limitations, and guidance for analysts.
