Malware analysis
Packed loaders and obfuscated payloads can stall an investigation before the real behavior is visible. Automate the preparation and give your analysts and AI agents a clearer path to understanding the threat.
IDA and Binary Ninja MCP are powerful. Packers and obfuscation can still bog them down.
BitBender automates unpacking and deobfuscation to make malware and game-cheat analysis dramatically more effective, for you and your AI agent.
Your tools. Your AI agent. A clearer view.
Less preparation. Deeper investigation.
The files you most need to understand are often the hardest to analyze.
Packed loaders and obfuscated payloads can stall an investigation before the real behavior is visible. Automate the preparation and give your analysts and AI agents a clearer path to understanding the threat.
Understand what a cheat does beneath its protection. Recover useful logic to investigate game interaction, memory manipulation, and concealed behavior, giving anti-cheat teams more to work with.
Our automated services handle the work that gets between your analysis tools and the code you need to understand.
Recover code and data beneath packing layers. Spend less of your investigation preparing a file and more of it understanding what the file does.
Recover imports, entry points, and executable structure. Give your disassembler and AI agent a more useful view of the program.
Reduce the complexity that hides meaningful behavior. Help analysts and AI agents follow the code that matters to the investigation.
Every sample is different. Specific coverage and recovery options are discussed directly.
Talk to usIDA Pro and Binary Ninja MCP let AI agents explore functions, follow references, and reason about program behavior. Packing and obfuscation can bury that work under layers of code that hide what you actually care about.
Automated unpacking and deobfuscation can dramatically improve malware analysis by clearing away the work that bogs down an investigation. The same preparation helps anti-cheat researchers follow the behavior hidden inside protected game cheats.
BitBender uses BLARE2, the same framework that CodeDefender is built on. Built and owned by Aftermath Labs.
Discuss your workflow API & agent integrations · In developmentPublished research from Aftermath Labs, the team behind BitBender. See what code recovery makes possible.
Recovered 815 of 865 virtualized functions across four kernel drivers, turning protected logic back into native code for analysis.
Read case studyUsed BLARE2 to simplify virtualized code and rebuild an executable function, with original and recovered output compared in IDA.
Read case studyRecovered key functions from a game cheat’s UEFI implant, revealing behavior across the boot chain, kernel, and hypervisor to inform detection research.
Read case studyFrom binary recovery to a full investigation and report, we scope the work around your goals.
Tell us about the malware or game cheats you’re investigating, your analysis tools, and what you need to understand.
Choose automated recovery, specialist consulting, or a full investigation and report. We agree on deliverables and sample-handling requirements.
Bring recovered artifacts into IDA, Binary Ninja, or your MCP workflow. Or have our team complete the analysis and deliver a full technical report.
Have something more specific in mind?
Let’s talk about itBoth. Malware research and game-cheat analysis are our primary use cases. We help analysts, threat researchers, and anti-cheat teams work through native binaries that are difficult to understand because of packing or obfuscation. Specific coverage depends on the sample.
MCP gives AI agents powerful access to your analysis tools, but packed and obfuscated code can still bog down their reasoning. BitBender prepares clearer code and structure for those tools, helping analysts and agents spend more of their effort investigating the underlying behavior.
Yes. Aftermath Labs offers deobfuscation consulting for unusual protections, difficult samples, and work that needs a specialist beyond automated processing. We scope the approach and deliverables around your file and research goals.
Yes. Give us a target and tell us what you need to know. Aftermath Labs can handle unpacking, deobfuscation, devirtualization, and analysis, then deliver a full technical report covering the findings and supporting evidence. We agree on the research questions, scope, and deliverables before starting.
No. Recoverability varies by sample. Some projects may yield a reconstructed binary; others may yield useful code, structural improvements, or partial recovery. We discuss expected deliverables as part of scoping your project.
API access and agent workflows are part of the product direction. Contact us to discuss early integration requirements and availability.
Start with a description of your project using the contact form or email. We’ll agree on a suitable transfer method and handling requirements before you send files. Keep binary samples and sensitive material out of the initial inquiry.
Malware, game cheats, or a special case.
Tell us where your analysis gets stuck.
Want to offload it all? Ask us for a full investigation and technical report.
Prefer email? Our inbox is open.