Researchers and malware analysts documented how Garble obfuscation is complicating reverse engineering of Go-based malware, particularly around stripped function names and runtime string reconstruction. Walmart Global Tech described a proof-of-concept for recovering Go standard library functions by matching bytecode sequences instead of relying on .gopclntab, while Mandiant detailed how Garble's string transformations split and encrypt data into randomized state-machine logic that is rebuilt and decrypted at runtime. OpenAnalysis separately highlighted a Garble-protected Windows stealer sample whose recovered artifacts pointed to credential theft, wallet targeting, anti-analysis checks, and exfiltration activity.
A recent analysis of Amatera Stealer showed the operational impact of those techniques in the wild: a 32-bit Delphi loader retrieved and launched a heavily obfuscated Go third-stage payload, initially misleading analysis because Garble protection made strings and logic difficult to interpret. The analyst later determined the sample likely used Garble without literal encryption, with strings still present but constructed dynamically at runtime; recovered behavior included persistence via a scheduled task for shark.exe, plus network indicators tied to the malware's infrastructure and a DNS lookup for data-seed-prebsc-2-s1.binance.org resolving to 109.172.87.40.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Runtime inspection of the Amatera sample revealed persistence via a scheduled task adding shark.exe, one malicious IP address in memory, and a DNS query to data-seed-prebsc-2-s1.binance.org resolving to 109.172.87.40.
The analyst updated the Amatera sample assessment to note that the Go payload appeared to use Garble without the -literals option, correcting an earlier belief that literal encryption was preventing tooling from recovering strings.
A GitHub malware analysis report examined a sample fetched from Amatera C2 infrastructure at h4.possumdefense.digital/shark.bin, identifying a 32-bit Delphi loader that unpacked a heavily obfuscated Go third stage.
A Google Cloud blog post from Mandiant detailed Garble's split string obfuscation transformation, showing how strings are chunked, encrypted, and reconstructed at runtime through a randomized state-machine generated with Go AST constructs.
OpenAnalysis published a raw artifact dump from a Windows infostealer sample that included the string "BANDIT STEALER," numerous credential- and wallet-theft targets, anti-analysis checks, and the endpoint mtls://159.223.189.221:8888.
A Walmart Global Tech blog post described a proof-of-concept method for de-obfuscating Go binaries by matching standard library functions via bytecode sequences, including tests against unobfuscated, name-mangled, and VirusTotal samples.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcecloud.google.com
Open sourceresearch.openanalysis.net
Open sourcemedium.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.