← All writing

Static Devirtualization of Themida

I co-authored a new article with IDontCode on the Aftermath Labs blog:

Static Devirtualization of Themida

The article demonstrates devirtualization of CodeVirtualizer/Themida protected code. The techniques apply to pretty much every virtual machine based obfuscator (VMProtect, VxLang, EagleVM, …), requiring only minor modifications for each.

It covers:

  • Guided symbolic evaluation: lifting native instructions into an IR and concretizing control flow as optimizations resolve unknown branch destinations, starting with a concrete stack pointer.
  • A small set of optimizations running to convergence: constant promotion and memory modeling, constant folding, dead store elimination, instruction combination and branch folding are enough to collapse the VM scaffolding.
  • VM-specific parts: VMEXIT classification by stack displacement, tracking the virtual instruction pointer to recognize loops, and Themida’s VJCC handler.
  • Lowering back to native code: dead dependency analysis, stack pointer rewriting, and why avoiding register spills matters for reinsertion.

The original, virtualized and devirtualized binaries are available at backengineering/themida-devirt.

If you are new to the topic, my posts on lifting and Mergen are a good starting point.

Read the full article on Aftermath Labs →