Researchers analyzing a SystemBC malware sample found it was protected by VMProtect 3.6+, which used layered anti-analysis techniques to frustrate debugging and unpacking. The protection chain reportedly included multiple debugger-detection methods, direct system calls, Windows build-number validation through structures such as KUSER_SHARED_DATA, fresh NTDLL remapping, and syscall-number extraction designed to evade user-mode hooks. The sample also appeared to rely on well-known anti-debugging and evasion patterns documented in public research, including low-level checks associated with segment handling and other debugger-detection tricks.
The analysts said VMProtect also performed anti-virtualization checks using CPUID, trap-flag behavior, and firmware-table inspection, exposing artifacts left by some older VirtualBox environments. To bypass those defenses, they modified ScyllaHide to spoof additional version fields, hook more APIs, change section-mapping behavior, and suppress firmware-table results. Those countermeasures allowed them to debug and unpack the malware, revealing that the SystemBC payload had been packed a second time beneath the VMProtect layer.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Researchers examined a SystemBC malware sample protected with VMProtect 3.6 or later and documented anti-debugging, direct-syscall, fresh-NTDLL remapping, and VM-detection techniques used by the packer. After modifying ScyllaHide to spoof additional version fields, hook more APIs, alter section mapping, and suppress firmware-table results, they were able to debug and unpack the sample and found the payload was packed a second time.
The analysis notes that older VirtualBox versions exposed virtualization through a trap-flag bug that pointed the exception EIP to the wrong instruction. It states this issue was fixed in VirtualBox version 7.0.4.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cyber.wtf
Open sourceevasions.checkpoint.com
Open sourceanti-debug.checkpoint.com
Open sourcegeoffchappell.com
Open sourcemalwaretech.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.