Elastic Security Labs found that Claude Opus 4.6, used as an autonomous static reverse-engineering agent, recovered passwords from 40% of 20 evaluable binaries protected by default Tigress obfuscation. JIT obfuscation, layered virtualization, and combinations of transformations significantly increased analysis cost and time or prevented recovery altogether.
Researchers developed three inexpensive protections—Matryoshka Wall, Double Fond, and Dispatch Maze—to exploit LLM static-analysis limits, context and budget constraints, and shortcut biases. The techniques delayed or blocked password recovery even when the model identified the broad obfuscation approach; Elastic cautioned that the protections primarily affect automated static analysis and may become less effective as agents gain dynamic execution capabilities.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
Using a controller-worker setup with IDA Pro and static analysis tooling, Elastic evaluated Claude Opus 4.6 against 20 evaluable default Tigress-obfuscated password-checking binaries. The model solved 40% of targets, while JIT/JitDynamic, nested virtualization, and heavy transformation combinations substantially increased cost or prevented recovery.
Elastic conducted an ON Week research project examining obfuscation techniques intended to hinder LLM-driven reverse engineering, including the Matryoshka Wall, Double Fond, and Dispatch Maze designs.
The GnuPG project released Libgcrypt version 1.12.2 from the LIBGCRYPT-1.12-BRANCH branch.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.