Habr•July 22, 2026•🇷🇺Translated from Russian

187,064 Instructions for One Flag: Reverse Engineering HTB Callfuscated Insane Challenge

The HackTheBox challenge Callfuscated presents a stripped 64-bit ELF binary that requests a password and prints either Correct or Incorrect flag. Inside the binary lies a heavily obfuscated verification routine built from four complementary techniques that survive static analysis but collapse under concrete execution.

The Obfuscation Arsenal

The protection consists of a custom VM whose bytecode resides in a 586-element array called program[]. A dispatcher reads the current program counter, fetches an opcode, and dispatches to handlers. Every arithmetic primitive is further expanded with Mixed Boolean-Arithmetic expressions. Opaque predicates double the control-flow graph with branches whose outcome is known at compile time. Finally, genuine instructions are wrapped inside thousands of call gadgets of the form pop r8; <insn>; call next, producing the 187,064-instruction count mentioned in the title.

Dynamic Reconnaissance

Because all four layers are execution-dependent, the author recorded a full instruction trace using ptrace with PTRACE_SINGLESTEP on a known input. The resulting log contained 187,064 lines together with register values after each instruction inside the image range 0x401000–0x40d000. A separate memory dumper extracted the VM program array and stack frames directly from the running process.

Building a Faithful Emulator

The trace was replayed inside a custom x86-64 emulator written in Python that parsed objdump output and implemented handlers for the thirty opcodes actually encountered. Two notable bugs were corrected during validation:

  • rand() is invoked from four distinct call sites (0x409235, 0x40ad5b, 0x40af37, 0x40b10b) for a total of 192 calls; each return address must be calculated as call-site + 5 rather than assuming a single fixed location.
  • Operand-size detection used a naïve substring check that incorrectly treated “DWORD PTR” as containing “WORD”, truncating 32- and 64-bit memory accesses.

After these fixes the emulator matched the original trace line-by-line and reached the final instruction at address 0x40b537 with eax equal to 0xffffffff, exactly as the real binary behaves on an incorrect password.

Recovering the VM Semantics

With a working emulator the author dumped the data stack after every dispatch and decoded the 586 VM instructions. The bytecode implements a simple stack machine whose relevant operations are:

  • PUSH imm – push constant
  • H2 – addition (used to compute input buffer address 0x40f080)
  • DEREF – read input byte
  • H5 – multiply accumulator by 256
  • H7 – add next byte
  • G8 / G3 – XOR with per-group constants

Consequently every four input characters are accumulated into a 32-bit big-endian word. Eight such words are XORed with the following constant pairs:

  • (0x0915033a, 0x41414141)
  • (0x427d7872, 0x11111111)
  • (0x30310a00, 0x55555555)
  • (0x2a052e32, 0x5a5a5a5a)
  • (0xcff5ecdf, 0xaaaaaaaa)
  • (0x1914031e, 0x77777777)
  • (0xf6f7c6ad, 0x99999999)
  • (0x6c6a524e, 0x33333333)

The resulting 32-bit values must all be zero for the password to be accepted. Solving each equation yields the flag bytes directly: HTB{******_**_***_********_*_**}.

Conclusion

The exercise demonstrates that even an extreme combination of VM-based dispatch, MBA, opaque predicates and call obfuscation remains vulnerable once execution is recorded and replayed. All four techniques ultimately depend on concrete runtime values that a faithful emulator can capture and simplify.

Related articles

Habr•Malware & Botnets

Leaked DarkSword iOS Exploit Chain 'P7' Now Steals Crypto Wallet Seeds and Keystores

A third build of the P7 variant of the leaked DarkSword iOS exploit chain has been identified, featuring a new lure site themed around Chinese online casinos and a fresh command server. The chain exploits six vulnerabilities, including three zero-days, to deploy an implant that decrypts the keychain directly on the device and extracts seed phrases from wallets such as imToken, Trust Wallet, and Phantom. Unlike the original GHOSTBLADE, P7 rewrites the C2 agent to focus exclusively on wallet data while retaining the core TaskRop and MIG-filter bypass modules. Passive analysis of public sources also uncovered the long-running 'qqtime' delivery cluster that pairs DarkSword with the older Coruna chain for broader iOS coverage. The operator uses channel codes to support multiple affiliate distributors and employs an AppleKeyStore oracle to decrypt keychain items locally before exfiltration.

BoletimSec•Malware & Botnets

Censys Exposes DarkSword iOS Exploit Platform and Coruna Crypto Wallet Stealer

Censys has disclosed the inner workings of DarkSword, a commercial platform that sells remote access to iOS devices, along with its associated malware Coruna that targets cryptocurrency wallet recovery keys. The infrastructure was exposed between September 15 and 17, allowing researchers to analyze the full attack chain starting from a WebKit and JavaScriptCore exploit delivered through the browser. After escaping the Safari sandbox and reaching the kernel, the platform deploys three layers including a flag, controller, and main implant. Coruna then scans the device for BIP39-compliant seed phrases stored in photos and Apple Notes across 19 targeted wallet applications such as MetaMask, Phantom, Trust Wallet, Coinbase, Exodus, imToken, Bitpie, and BitKeep. The exposed server contained 11 victim recovery keys, 179 directories of extracted data, and 75 operator accounts, indicating a structured commercial operation with agent accounts, commissions, and device quotas. Confirmed infections affect devices running iOS 16.1 and 16.3.1, while Apple has extended patches to additional iOS 18 devices. Maintaining updated iOS versions remains the primary defense against this threat.

Securitylab•Malware & Botnets

How Malware Evades Sandboxes: Detection Techniques and Defense Strategies

Sandboxes have become a standard tool for analyzing suspicious files delivered via email, websites, messengers, and cloud storage. Modern malware often avoids detection by identifying virtual environments rather than directly attacking the sandbox. Techniques include checking for virtualization artifacts, system parameters, hardware signatures, network indicators, user activity, and timing delays. Reports such as Picus Red Report 2026 show technique T1497 returning to the top five most common MITRE ATT&CK methods. Examples like Blitz, GootLoader, and LummaC2 demonstrate environment checks and behavioral evasion. Effective defense requires combining multiple analysis methods, realistic sandbox profiles, pre-delivery inspection, and integration with other security controls.

BoletimSec•Malware & Botnets

Realtek Jungle SDK Flaw CVE-2021-35394 Fuels Cling Botnet Spread Across Routers

Researchers at Nozomi Networks have observed a sharp rise in exploitation attempts against CVE-2021-35394, a critical remote code execution vulnerability in the Realtek Jungle SDK. The flaw, rated 9.8 on the CVSS scale and disclosed five years ago, is being used to deploy the Cling botnet on routers and video recorders. The affected SDK is embedded in products from multiple vendors, leaving large numbers of devices exposed because firmware updates are rarely applied. Cling carries exploits for seven distinct vulnerabilities targeting Realtek, Linksys, MVPower, TBK, LB-LINK, FiberHome and China Mobile hardware. Once installed, the malware performs recursive scanning, spreads like a worm, manipulates TCP tunnels and proxies, and participates in DDoS attacks. Its command-and-control channel hides instructions inside STUN protocol transaction IDs, impersonating legitimate responses from Google public STUN servers. FortiGuard Labs has confirmed the findings and tracks the variant as ClingSTUN.