typeconceptconfidencehighcreated2026-08-04updated2026-08-04golanganti-analysismasqueradeevasion

Go Fake Source-Path Masquerade

Anti-analysis technique in which a Go-compiled binary embeds fake vendor source paths in its program counter / line number table (pclntab), misleading analysts into attributing the binary to a legitimate software vendor.

Mechanism

Go's runtime stores source-file names in the pclntab section for stack traces and profiling. Even when compiled with -ldflags="-s -w", these paths survive. A malware author can structure their build environment so that source paths appear to come from a legitimate vendor (e.g. Microsoft.WindowsSoundDiagnostics) rather than the actual project directory.

Impact

  • Confuses static analysis tools and human reviewers during initial triage
  • May cause false-negative detections if vendor-whitelist rules trust the apparent origin
  • Survives standard symbol stripping because the paths are embedded in the runtime metadata, not the symbol table

Detection

  • Inspect pclntab strings with rabin2 -z or strings
  • Cross-reference claimed vendor paths against known legitimate product lines
  • Look for mismatches: a "Microsoft" path in a binary with no Authenticode signature, no .rsrc icons, and no known Microsoft build fingerprints

Observed In

Related Concepts