Go Fake Source-Path Masquerade
Anti-analysis technique in which a Go-compiled binary embeds fake vendor source paths in its program counter / line number table (pclntab), misleading analysts into attributing the binary to a legitimate software vendor.
Mechanism
Go's runtime stores source-file names in the pclntab section for stack traces and profiling. Even when compiled with -ldflags="-s -w", these paths survive. A malware author can structure their build environment so that source paths appear to come from a legitimate vendor (e.g. Microsoft.WindowsSoundDiagnostics) rather than the actual project directory.
Impact
- Confuses static analysis tools and human reviewers during initial triage
- May cause false-negative detections if vendor-whitelist rules trust the apparent origin
- Survives standard symbol stripping because the paths are embedded in the runtime metadata, not the symbol table
Detection
- Inspect
pclntabstrings withrabin2 -zorstrings - Cross-reference claimed vendor paths against known legitimate product lines
- Look for mismatches: a "Microsoft" path in a binary with no Authenticode signature, no
.rsrcicons, and no known Microsoft build fingerprints
Observed In
- unclassified-go-pe64 Cluster B (
9665ccc9) — fakeMicrosoft.WindowsSoundDiagnosticspath
Related Concepts
- golang-stealer-build-pattern — Build/RE concept page for Go malware build artefacts
- social-engineering-filename-lure — Companion masquerade technique at the filename layer