In the summer of 2026, Invoke RE began seeing the Efimer loader delivering a Pyarmor infection chain leading to a JavaScript clipper variant. We used the Frida dynamic instrumentation framework to break its protections to recover secondary payloads.
In this blog post we discuss the creation of Binary Ninja MCP. An MCP server that allows AI to interact directly with a Binary Ninja database in order to reverse engineer binaries.
In this blog post we explore using Binary Ninja and emulation to address obfuscation implemented by an open source obfuscator named Garble that is used by red team operators and malware authors to inhibit reverse engineering efforts.
Throughout this blog post we provide Binary Ninja automation strategies for analyzing obfuscation techniques implemented by Qakbot.