Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
VMPacker — ARM64 ELF Virtual Machine Protection System | Kitploit
Tools/GitHubGitHub/leochen-coremind/vmpacker
Embedded Systems SecurityExploit FrameworksIoT SecurityVulnerability AnalysisReverse EngineeringFuzzingPenetration TestingMobile SecurityHardware SecurityBinary AnalysisAnti-Bot
477170226 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHub
leochen-coremind/vmpacker

VMPacker

ARM64 ELF Virtual Machine Protection System

View Repository

🛡️ VMPacker

ARM64 ELF Virtual Machine Protection System

Translate ARM64 native instructions into custom VM bytecode for function-level code protection

🇨🇳 中文文档 • Features • Architecture • Quick Start • Usage • License


Overview

VMPacker is a Virtual Machine Protection (VMP) system for ARM64 (AArch64) Linux ELF binaries. It decodes target function's native ARM64 instructions into an intermediate representation, translates them into custom VM bytecode, and injects an embedded VM interpreter into the ELF file. At runtime, protected functions are executed by the VM interpreter instead of natively.

Core Concept

ARM64 Native Code  →  Decode  →  Translate  →  Custom VM Bytecode
                                                      ↓
                    Original ELF  ←  Inject  ←  VM Interpreter Stub

Features

🔄 Instruction Translation Engine

  • 63 VM instructions — covering ALU, memory, branch, syscall, and more
  • Table-driven decoder — pattern matching based on the ARM Architecture Reference Manual
  • 121 ARM64 instructions supported (base A64 100% coverage), including:
    • Arithmetic/Logic (ADD, SUB, MUL, AND, ORR, EOR, LSL, LSR, ASR, MVN, BIC, ORN, EON...)
    • Multiply-Extend (MADD, MSUB, SMADDL, SMSUBL, UMADDL, UMSUBL, SMULH, UMULH, UDIV, SDIV)
    • Data Movement (MOV, MOVZ, MOVK, MOVN)
    • Memory Access (LDR, STR, LDP, STP, LDPSW, LDADD, CAS, LDAR, STLR, LDAXR, STLXR — various widths and addressing modes)
    • Branch Control (B, BL, BR, BLR, RET, B.cond, CBZ/CBNZ, TBZ/TBNZ)
    • Conditional Select (CSEL, CSINC, CSINV, CSNEG, CCMP, CCMN)
    • Bitfield (UBFM, SBFM, BFM, EXTR)
    • Bit Manipulation (CLZ, CLS, RBIT, REV, REV16, REV32)
    • Carry Arithmetic (ADC, ADCS, SBC, SBCS)
    • SIMD Load/Store (LD1, ST1)
    • System/Barriers (SVC, MRS, MSR, ADRP/ADR, DMB, DSB, ISB, HLT, BRK, PRFM)

🔐 Multi-Layer Protection

LayerTechniqueDescription
VM ProtectionCustom ISARandomly mapped opcodes — reverse engineers cannot directly identify instruction semantics
OpcodeCryptorPer-instruction opcode encryptionenc[pc] = op[pc] ^ (key ^ (pc * 0x9E3779B9))
Bytecode ReversalExecution order reversalInstructions stored in reverse order; interpreter traverses backwards
Token Entry3-instruction trampolineOriginal function replaced with tokenized entry, hiding actual bytecode location
Indirect DispatchFunction pointer jump tableFilled at runtime on the stack, breaking IDA cross-references

🖥️ GUI

  • Cross-platform desktop app built with Wails v2 (Go + Vue 3)
  • Element Plus UI components
  • Symbol function selection + manual function input (protect by address range)
  • One-click protection with real-time log output
Main Interface Function Analysis Protection Options
Function List Analysis & Selection Protection Options
Protection Execution Protection Complete
Real-time Logs Protection Complete

Architecture

vmp/
├── cmd/vmpacker/          # CLI entry point
│   ├── main.go            # CLI argument parsing + orchestration
│   └── vm_interp.bin      # Compiled VM interpreter (GCC, go:embed)
│
├── pkg/                   # Go core library
│   ├── arch/arm64/        # ARM64 architecture support
│   │   ├── decoder.go     # Table-driven instruction decoder (implements vm.Decoder)
│   │   ├── decode_*.go    # Decode pattern tables (DP-IMM/DP-REG/Branch/LdSt)
│   │   ├── translator.go  # ARM64 → VM bytecode translator
│   │   ├── tr_alu.go      # ALU instruction translation
│   │   ├── tr_branch.go   # Branch instruction translation
│   │   ├── tr_loadstore.go # Memory instruction translation
│   │   ├── tr_bitfield.go # Bitfield instruction translation
│   │   └── tr_special.go  # Special instructions (ADRP/ADR)
│   ├── vm/                # VM ISA definitions
│   │   ├── types.go       # Shared types + interfaces (Decoder/Translator/Packer)
│   │   ├── opcodes.go     # 58+ VM opcode definitions (randomly mapped values)
│   │   └── disasm.go      # VM bytecode disassembler
│   └── binary/elf/        # ELF binary manipulation
│       ├── packer.go      # ELF VMP injection (PT_NOTE hijack, trampoline generation)
│       └── trampoline.go  # Trampoline code generation
│
├── stub/                  # C VM interpreter (compiled to PIC flat binary)
│   ├── vm_interp_clean.c  # Interpreter main loop + entry points
│   ├── vm_types.h         # VM CPU context (vm_ctx_t)
│   ├── vm_opcodes.h       # C-side opcode definitions (synced with opcodes.go)
│   ├── vm_decode.h        # Bytecode read utilities
│   ├── vm_token.h         # Token encode/decode + descriptor table
│   ├── vm_dispatch.h      # Indirect dispatch jump table
│   ├── vm_crc.h           # CRC32 integrity check
│   ├── vm_sections.h      # Handler section scattering macros
│   ├── vm_interp.lds      # Linker script
│   └── vm_handlers/       # Modular instruction handlers
│       ├── h_alu.h        # Arithmetic/logic operations
│       ├── h_mem.h        # Memory access
│       ├── h_branch.h     # Branch/jump
│       ├── h_cmp.h        # Compare/conditional
│       ├── h_mov.h        # Data movement
│       ├── h_stack.h      # Stack (PUSH/POP)
│       └── h_system.h     # System (SVC/MRS/BLR/BR/RET)
│
├── vmp-gui/               # Wails GUI frontend
│   ├── frontend/          # Vue 3 + Element Plus
│   └── backend/           # Go backend bindings
│
└── build/                 # Pre-compiled tools + test artifacts

Modular Design

The project uses an interface-driven modular architecture, making it easy to extend to new ISAs and binary formats:

// Architecture decoder interface — extensible to x86, RISC-V
type Decoder interface {
    Decode(raw uint32, offset int) Instruction
    InstName(op int) string
}

// Bytecode translator interface
type Translator interface {
    Translate(instructions []Instruction) (*TranslateResult, error)
}

// Binary format injector interface — extensible to PE, Mach-O
type Packer interface {
    Process() error
}

Protection Pipeline

graph LR
    A[Input ELF] --> B[Locate Target Function]
    B --> C[Extract ARM64 Instructions]
    C --> D[Decode ARM64]
    D --> E[Translate to VM Bytecode]
    E --> F[XOR Encrypt Bytecode]
    F --> G[Inject VM Interpreter]
    G --> H[Generate Trampoline]
    H --> I[Replace Function Entry]
    I --> J[Output Protected ELF]
Download Tool