Mastodon Mastodon Mastodon Mastodon

Obfuscation

Updated: · CyberSecureFox Editorial Team

Obfuscation is the deliberate transformation of code or data to make it hard to read and analyse while keeping its behaviour unchanged.

How obfuscation works

Obfuscation does not change what a program does, only how it looks. Common techniques include:

  • renaming variables and functions to meaningless strings;
  • encrypting or encoding strings, such as URLs and commands, and decoding them only at run time;
  • control-flow flattening and junk code that hide the real logic;
  • splitting and concatenating commands, a favourite trick in PowerShell and JavaScript;
  • packing the whole binary with a packer so that it unpacks itself in memory.

Why obfuscation matters for security

Almost all modern malware is obfuscated. It helps attackers bypass signature-based antivirus, slows down reverse engineering and hides indicators such as command-and-control addresses. Web skimmers injected into online shops hide their code in heavily obfuscated JavaScript or even inside image files, and phishing kits obfuscate HTML to evade mail filters. The open-source tool Invoke-Obfuscation showed how easily PowerShell commands can be disguised.

Obfuscation also has legitimate uses: developers protect intellectual property and licensing logic in mobile apps and JavaScript with tools such as ProGuard or commercial protectors.

How defenders deal with it

  • Detect behaviour rather than strings: EDR sees what a script does once it is decoded.
  • Use the Windows Antimalware Scan Interface (AMSI) and PowerShell script-block logging, which record deobfuscated content.
  • Analyse samples dynamically in a sandbox and use deobfuscation tools such as CyberChef or de4dot.
  • Treat heavy obfuscation itself as a warning sign in scripts and documents.
Synonyms:
code obfuscation