Pages from a Sword-Maker's Notebook pt. III, "The cursed blade"
Vyrus
ShmooCon XX (Final) · Day 2 · Bring It On
Overview
In "Pages from a Sword-Maker's Notebook pt. III, 'The cursed blade'," security researcher Vyrus unveils a compelling narrative of how he ingeniously transformed an open-source Mimikatz packer into an intelligence-gathering instrument. The talk, delivered at ShmooCon, details Vyrus's journey from creating a utility for ethical offensive security to discovering its adoption by malicious actors, prompting him to subtly backdoor his own tool. This act of turning the tables allowed him to collect remarkable operational security (OpSec) intelligence on the various individuals and groups compiling and using his software, all without violating legal boundaries.

Key moments
- 0:00 Sentimental opening and ShmooCon's personal history
- 2:40 Introduction to custom malware used by bad guys
- 3:20 Explaining Mimikatz and Go MIM cats packer
- 4:20 Discovery of Go MIM cats on VirusTotal
- 5:20 Understanding how his tool reached VirusTotal
- 6:00 Transition to backdooring and packer mechanism
- 6:20 Deep dive into Go MIM cats' three-piece architecture
Pages from a Sword-Maker's Notebook pt. III, "The cursed blade"
Speakers: Vyrus
Conference: ShmooCon
YouTube: https://www.youtube.com/watch?v=yIutY_X2FcU
Overview
In "Pages from a Sword-Maker's Notebook pt. III, 'The cursed blade'," security researcher Vyrus unveils a compelling narrative of how he ingeniously transformed an open-source Mimikatz packer into an intelligence-gathering instrument. The talk, delivered at ShmooCon, details Vyrus's journey from creating a utility for ethical offensive security to discovering its adoption by malicious actors, prompting him to subtly backdoor his own tool. This act of turning the tables allowed him to collect remarkable operational security (OpSec) intelligence on the various individuals and groups compiling and using his software, all without violating legal boundaries.
Vyrus, a seasoned security professional with a background spanning both offensive consulting and blue team operations, presents a unique case study in threat intelligence. His methodology involved embedding build-time information and screenshots directly into the compiled binaries of his Go-based Mimikatz packer, Go MIM cats. By leveraging VirusTotal submissions, he was able to "drag the swamp" of collected samples, decrypt the embedded data, and expose a diverse array of users—ranging from suspected nation-state actors and corporate entities to independent researchers and even casual "gamer" hackers. The talk serves as both a fascinating technical deep dive and a potent reminder of the critical importance of source code review and stringent OpSec practices in the cybersecurity landscape.
The significance of this presentation extends beyond mere technical curiosity. It underscores the dual-use nature of many security tools and the ethical tightrope walked by their creators. Vyrus demonstrates how an understanding of adversary tradecraft, coupled with a creative approach to intelligence collection, can yield invaluable insights into the global threat landscape. His findings not only provided specific details on the identities and environments of those using his tool but also confirmed suspicions about certain organizations' affiliations with state-sponsored activities, making this a pivotal contribution to the discourse on adversary tracking and supply chain security.
Background
▶ Watch: Sentimental opening and ShmooCon's personal history (0:00)
The genesis of this talk lies in Vyrus's creation of Go MIM cats, a Mimikatz packer written in Go. Mimikatz itself is a notorious and powerful post-exploitation tool primarily known for its ability to extract plaintext credentials, NTLM hashes, Kerberos tickets, and more from the Local Security Authority Subsystem Service (LSASS) process in Windows. While widely used by ethical hackers and red teams for penetration testing and adversary simulation, its effectiveness means it is also a staple in the arsenal of actual threat actors globally.
Vyrus developed Go MIM cats during his "consulting days," a period likely focused on offensive security engagements. The tool's purpose was to package Mimikatz in a way that could evade detection, presumably for legitimate red team activities. Written in Go, it offered certain advantages, which would later become a focal point of the talk. However, the dual-use nature of such a powerful utility meant it was only a matter of time before it attracted the attention of malicious actors.
The problem Vyrus observed, leading to the events of this talk, was the widespread adoption of Go MIM cats by "bad guys." He noticed its regular appearance on VirusTotal, a multi-antivirus scanning platform. Crucially, the consistent updates to VirusTotal suggested that blue teams were actively fingerprinting his tool at scale. This widespread detection by antivirus (AV) vendors—with detection rates jumping from "zero out of 60" to "35 plus"—provided Vyrus with a legitimate pretext to "update" his software. This update, ostensibly to modify the static signature and improve evasion, became the vehicle for embedding his intelligence-gathering backdoor, setting the stage for his unique experiment in adversary tracking.
Key Findings
▶ Watch: Explaining Mimikatz and Go MIM cats packer (3:20)
The central discovery of Vyrus's "cursed blade" experiment was the successful, covert collection of operational intelligence from a diverse spectrum of users compiling and deploying his backdoored Go MIM cats. By embedding detailed build-time information and screenshots directly into the binaries, and then retrieving these from samples submitted to VirusTotal, Vyrus gained unprecedented insights into the identities, locations, and environments of those utilizing his tool.
His findings revealed a global tapestry of users, ranging from sophisticated state-sponsored groups to individual researchers and even hobbyists:
- German Google Employee: An individual identified as "Chris PSD" in Germany, whose environment variables and a screenshot indicated an interest in pentesting and blockchain, and who was actively employed by Google.
- Chinese I-Soon Operator: A particularly significant discovery was an operator using the username "scoop" from a specific building in Shenzhen, China, linked to the notorious APT group I-Soon. This group, known for military-backed cyber operations against Western and Asian targets, was confirmed through IP geolocation and the user's GitHub activity, which showed a commit on the day of the build. Vyrus noted this intelligence was shared with "certain parties" and was "useful in stuff."
- Russian Speaker: A user identified by Cyrillic text and an IP address in Russia. While specific identity remained elusive, the presence indicated Russian-speaking operators.
- Tencent Employees (Hong Kong & US): Two distinct instances pointed to employees of Tencent, a major Chinese technology conglomerate. One was clearly operating from a Tencent office in Hong Kong, using a Tencent laptop, with their romanized username translating to Mandarin. Another instance traced to Tencent IP space in the US (via AT&T), also showing Chinese localization. Vyrus highlighted that the US government had recently classified Tencent as a military organization, adding significant weight to these findings.
- Japanese Multi-Lingual Researcher/Hacker: An individual in Japan whose browser tabs showed an eclectic mix of Russian, other Slavic languages, Mandarin, and Japanese, alongside Tor Browser. This suggested either broad research interests or a highly skilled operator working across multiple linguistic contexts.
- US "Gamer Kid": A user in Nashville, Tennessee, whose system was laden with gaming-related tools like CPU-Z, Nvidia utilities, and overclocking software, indicating a personal machine and potentially a younger, less OpSec-aware individual.
- Chinese Jilin University System: A generic system in China, likely a shared university machine at Jilin University (a major Chinese research institution), operating on the Chinet backbone, suggesting significant access and resources.
- Israeli Operator: A complex scenario involving an operator in Israel using an Amazon Workspace, RDPing into a Digital Ocean machine. The desktop revealed a wealth of hacker tools (ScareCrow, PSExec, BloodHound) and a Microsoft Teams call to a "David Shaw," potentially linking to an IT service company in Israel.
- Portuguese "Nerd": A user in Portugal with extensive Python development tools, DJ software (Zulu DJ, NCH Suite), VPNs, and Portuguese memes on their desktop, indicating a versatile individual "playing on both sides of the line."
- Chinese Red Teamer: Another Chinese user operating on the Chinet backbone, whose system featured red teaming tools like Neo4j and BloodHound, along with Android development tools, Java, R, and multiple Python environments.
- Repeated Japanese User: The same Japanese user's system appeared twice, suggesting they either submitted it multiple times or it was repeatedly picked up by VirusTotal after multiple uses.
These findings collectively demonstrated the power of Vyrus's method to unmask operational details, providing concrete evidence of the backdoor's efficacy and revealing the diverse landscape of those engaging with offensive security tools. The experiment concluded when Chinese users discovered the backdoor, noting the data collection but also that it was not exfiltrating externally—prompting Vyrus to remove the backdoor and issue a "defanged" update.
Technical Deep Dive
▶ Watch: Discovery of Go MIM cats on VirusTotal (4:20)
The technical ingenuity of Go MIM cats and its subsequent backdoor lies in its multi-stage architecture and the clever use of Go language features, combined with an understanding of operating system internals and AV evasion techniques.
The original Go MIM cats operates in three distinct phases:
- The Packer:
- This component initiates by downloading a specific, explicit version of the Mimikatz binary directly from GitHub.
- It then unzips this binary in memory.
- Crucially, it "shell codifies" the executable using Donut. Donut is an open-source, in-memory userland loader (primarily developed by Ben Cates and others) that converts executables (like Mimikatz) into position-independent shellcode. This shellcode can then be loaded and executed directly from memory, bypassing the need to write the executable to disk and thus evading file-based detections.
- After shell codification, the resulting Mimikatz shellcode is split into two binary one-time pads. This is achieved by generating a random byte for every byte of the original shellcode and XORing it to create the first pad. The second pad is then derived by XORing the first pad with the original shellcode. These two pads are then written to disk. The use of one-time pads makes the stored components individually unintelligible without the other, adding a layer of obfuscation.
- The Stub:
- This is a standalone binary that contains the two obfuscated pads.
- Its primary function is to read these two pads from its own binary data segment.
- It then XORs the two pads back together in memory, reconstructing the original Mimikatz shellcode.
- Finally, it uses Donut's loading mechanism to execute this reconstructed shellcode directly from memory, running Mimikatz without ever dropping its executable form to disk.
- The Fixer:
- This component addresses a specific challenge with Go's runtime environment. In Go, variables containing data are typically placed in data segments, which are marked as non-executable by default for security reasons. Attempting to execute code from these segments (as the stub does with the reconstructed Mimikatz shellcode) would result in an immediate segmentation fault.
- The fixer's role is to modify the memory permissions of all relevant sections within the binary to be executable. Vyrus highlights a rather "hilarious" aspect of this: normally, marking all sections of a binary as executable is a glaring indicator of malware (a "1991 level" detection technique). However, due to the high entropy of Go binaries and the frequent changes in the Go runtime, most antivirus and anti-malware vendors have "given up trying to profile it section by section." This allows for a seemingly crude but highly effective evasion technique that still works "years later even with modern Go."
The Backdoor Implementation:
When Vyrus decided to "backdoor" Go MIM cats, he integrated the intelligence-gathering capabilities into the fixer.go component. This was done under the pretext of an "update" to evade detection, as the original tool had started being flagged by numerous AV vendors. The backdoored fixer.go performed the following actions at compile time:
- Information Collection: It gathered a wealth of details about the compiling environment, including:
- The current user's home directory (
HOME). - The current username (
USER). - All environment variables present in the build environment.
- Screenshots of every attached monitor at the time of compilation.
- The public IP address of the host, obtained by querying
myexternalip.com. - Go-specific constants indicating the system's architecture (
GOARCH) and operating system (GOOS). - Obfuscation: This collected information was then XORed with a static key.
- Embedding: Crucially, the XORed, obfuscated data was shoved directly into the binary itself. Vyrus emphasized that this was a deliberate legal safeguard: the data was not exfiltrated over the internet to any external server (e.g., Dropbox, C2). This meant that for Vyrus to obtain the data, the compiled binary had to be willingly submitted to a public platform like VirusTotal, or otherwise provided to him. This distinction was key to avoiding legal grey areas concerning "stealing" data.
By embedding the data, Vyrus transformed each compiled instance of Go MIM cats into a self-contained intelligence capsule. When these capsules inevitably appeared on VirusTotal (submitted either by the users themselves or by blue teams detecting them), Vyrus could then download them, decrypt the embedded information, and gain a detailed snapshot of the adversary's build environment.
Demo / Proof of Concept
▶ Watch: Transition to backdooring and packer mechanism (6:00)
While the talk did not feature a live, interactive coding demonstration, the entire presentation served as a comprehensive retrospective "proof of concept" for the backdoored Go MIM cats. Vyrus meticulously walked the audience through the results of his intelligence-gathering operation, showcasing numerous slides, each representing a specific instance of his backdoored tool found on VirusTotal.
Each slide functioned as a mini-demonstration, illustrating the wealth of information successfully extracted from the compiled binaries. These visual exhibits typically included:
- Desktop Screenshots: High-resolution screenshots of the user's desktop(s) at the exact moment the tool was compiled. These images provided a rich visual context, revealing open applications (e.g., GitHub, RDP sessions, virtual machines, IDEs like VS Code, Ida Pro), desktop icons, and even personal details like weather widgets or memes.
- Extracted Metadata: Textual dumps of the information collected by the backdoor, such as:
- The user's username and home directory path.
- A comprehensive list of environment variables, which sometimes contained critical clues like Go proxy settings (e.g., Chinese endpoints) or internal domain names.
- The public IP address of the compiling machine, which Vyrus then used for geolocation to pinpoint the user's physical location, sometimes down to a specific building.
- The operating system and architecture (
GOOS,GOARCH).
Vyrus then provided a detailed analytical commentary for each case, piecing together the clues to build a profile of the user. For example, he demonstrated how:
- A user named "Chris PSD" with German language settings and a Google profile was identified.
- An IP address and a GitHub commit history confirmed an I-Soon operator in Shenzhen, China.
- Screenshots showing Tencent internal tools and Hong Kong IP addresses pointed to Tencent employees.
- The presence of Tor Browser, multiple languages in browser tabs, and specific IP locations revealed a Japanese operator with diverse interests.
- Gaming tools and a Nashville IP address identified a casual "gamer" hacker.
- The combination of an Amazon workspace, RDP to Digital Ocean, and a Microsoft Teams call provided a fascinating glimpse into an Israeli operator's workflow.
The cumulative effect of these detailed examples was a powerful validation of the backdoor's effectiveness. It clearly demonstrated how the backdoor worked by showing the recovered data and what insights could be gleaned from it, making the abstract technical concept tangible and impactful. The "demo" was, in essence, a year-long collection of forensic evidence presented in an engaging and analytical manner.
Defensive Implications
▶ Watch: Deep dive into Go MIM cats' three-piece architecture (6:20)
Vyrus's talk, while focused on an offensive technique, carries profound implications for cybersecurity defenders and offensive operators alike, highlighting critical areas for improved security posture and operational awareness.
- Mandatory Source Code Review: The most immediate and emphasized takeaway is the absolute necessity for individuals, especially those in offensive security roles, to always review the source code of any tool they intend to compile and run. Vyrus explicitly stated this lesson for one of the identified users: "read your Source before you compile it." Relying on open-source tools without understanding their full functionality can lead to inadvertent OpSec breaches, as demonstrated by the collection of sensitive build-time data.
- VirusTotal as an OSINT Source (and Risk): For defenders, the talk illustrates that VirusTotal can be a powerful source of open-source intelligence (OSINT). While primarily used for malware analysis, it can also be leveraged by tool authors (or others) to track the deployment and, in this unique case, the build environments of specific tools. Conversely, it serves as a stark warning to offensive operators: submitting samples (or having them submitted by AV systems) to VirusTotal can expose critical information about your identity, location, and operational setup if the malware itself is designed to collect it.
- Challenges in Go Binary Analysis: Vyrus highlighted that Go binaries present unique challenges for traditional signature-based detection mechanisms used by AV/EDR solutions. Due to Go's high entropy and frequent runtime changes, methods like section profiling (which would typically flag a binary with all executable sections as suspicious) often fail or are ignored. This means defenders need to evolve their analysis techniques for Go executables, moving towards more sophisticated behavioral analysis, memory introspection, and runtime monitoring rather than relying solely on static signatures.
- Operational Security (OpSec) for Offensive Operators: The talk serves as a critical lesson in OpSec for red teamers, penetration testers, and malicious actors. The sheer volume of personal and environmental data leaked (usernames, IPs, screenshots, installed tools, open browser tabs) underscores the importance of:
- Isolated Build Environments: Using dedicated, clean virtual machines or containers for compiling tools, devoid of personal information, corporate network access, or other sensitive data.
- Minimalist Environments: Only installing necessary tools in build environments to reduce the attack surface for information leakage.
- Network Isolation: Ensuring build systems are isolated from personal or corporate networks, and public IP addresses are obfuscated (e.g., via VPNs or Tor, if appropriate).
- Awareness of Tool Functionality: Understanding that any tool, even open-source, can contain hidden functionalities that compromise OpSec.
- Adversary Tracking and Threat Intelligence: The methodology demonstrated by Vyrus provides a novel framework for adversary tracking. By subtly modifying commonly used dual-use tools, intelligence agencies or well-resourced security teams could, if legally and ethically permissible, gain significant insights into the groups and individuals utilizing these tools. The specific identification of I-Soon operators and Tencent employees acting on behalf of the Chinese military showcases the high-value intelligence that can be derived from such unconventional methods, directly informing threat intelligence efforts.
In essence, Vyrus's "cursed blade" serves as a powerful case study, urging both sides of the cybersecurity divide to re-evaluate their practices—defenders to enhance their detection capabilities against evolving binary types and offensive operators to drastically improve their OpSec hygiene.
Key Takeaways
- Always review the source code of any tool before compiling and executing it. Blindly trusting open-source tools can lead to inadvertent operational security (OpSec) breaches, as demonstrated by the embedded data collection.
- Open-source tools, especially those with dual-use potential, can be subtly backdoored to gather intelligence on their users. This highlights a novel method for adversary tracking and the ethical considerations for tool developers.
- VirusTotal submissions can inadvertently expose sensitive build-time OpSec details. Whether submitted by the user or an automated system, these submissions can become a rich source of intelligence for those tracking specific binaries.
- Go binaries present unique challenges for traditional antivirus and endpoint detection and response (AV/EDR) systems. Their high entropy and dynamic runtime behavior can render static signature-based detection methods, even for "obvious" malware indicators, ineffective.
- High-value threat intelligence can be derived from unexpected sources. Vyrus's method provided specific, actionable intelligence on suspected nation-state actors (I-Soon, Tencent) and diverse individual operators globally.
- Offensive operators must maintain stringent OpSec in their build environments. Leaks of usernames, IP addresses, environment variables, and desktop screenshots can compromise individual identity and organizational affiliation, serving as a critical lesson for red teamers and malicious actors alike.
About the Speaker(s)
The speaker for this ShmooCon presentation is Vyrus. While specific titles or affiliations were not explicitly stated in the metadata or the initial portion of the transcript, Vyrus's narrative reveals a deep and extensive background in the cybersecurity field.
He describes himself as having been engaged in "consulting days," which typically implies a role in offensive security, such as penetration testing or red teaming. Subsequently, he transitioned to a "blue team job," where he gained access to a "big boy virus total account," indicating experience in defensive security, incident response, or threat intelligence. This dual perspective provides him with a well-rounded understanding of both offensive tradecraft and defensive detection challenges.
Vyrus also has a long and sentimental history with ShmooCon, recalling attending since "ShmooCon 3" and marking significant life milestones in relation to the conference, including his first party, bringing his oldest child, and meeting his wife. He mentions being part of the "949 Clan" in his earlier hacking days. His remote delivery for this talk was due to personal circumstances (ensuring his family and home were safe), underscoring a commitment to both his community and personal responsibilities. His confident and analytical presentation style reflects years of practical experience and deep technical knowledge in offensive tool development and intelligence gathering.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
Vyrus delivered a masterclass in turning the tables on adversaries, backdooring his Go-based MimiKatz packer to passively collect intelligence on its users. By embedding compilation-time data—including screenshots and environment variables—directly into the binary, and then leveraging VirusTotal submissions, he unveiled a fascinating trail of operators. The revelations, ranging from a Google pentester to confirmed I-Soon and Tencent-linked individuals, provided a stark, real-world glimpse into who is using these tools, all while navigating the precarious legal tightrope of such a tracking method.
Heather Calloway (CISO) — MUST SEE
Vyrus’s exploration of his backdoored Mimikatz packer is a masterclass in turning technical ingenuity into high-value intelligence, directly exposing critical gaps in institutional OpSec and supply chain trust. The talk offers irrefutable evidence of state-sponsored actors and corporate employees inadvertently leaking sensitive operational details, providing a stark, actionable lesson for CISOs, boards, and security leaders on the profound implications of unvetted open-source tools and lax build environment hygiene. This isn't just a clever hack; it's a direct window into adversary tradecraft and institutional vulnerability.