typetechniqueconfidencehighcreated2026-08-16updated2026-08-16obfuscationdefense-evasionpython-pyinstalleranti-analysis

PyArmor Runtime Obfuscation

PyArmor is a Python obfuscation tool that encrypts Python source code or bytecode and bundles a C-extension runtime (pyarmor_runtime.pyd on Windows) to decrypt and execute at load time. It is commonly used to protect Python payloads packed with PyInstaller.

Technique Details

  • Encryption: Python modules are AES-encrypted and wrapped in a C-extension loader. The decryption key is derived at runtime from hardware fingerprints or a hardcoded license.
  • Anti-tamper: The C-extension runtime verifies checksums of the protected scripts; modification causes silent failure.
  • Import hook: Replaces the standard Python import mechanism with a custom __import__ hook that decrypts modules on first access.
  • String protection: Literal strings in the Python source are encrypted at rest and decrypted at runtime.

Detection

  • Presence of pyarmor_runtime_000000\pyarmor_runtime.pyd in the PyInstaller TOC or extracted _MEI* temp directory.
  • pyarmor_runtime_000000 string in the binary overlay.
  • FLOSS and other string-decoding tools return only boilerplate; no plaintext C2, URLs, or configuration strings.

Limitations for Analysts

  • Static string extraction is largely defeated.
  • Dynamic analysis requires running the sample (or attaching a debugger to the Python process after the runtime decrypts).
  • Memory dumps of the running process contain decrypted scripts but extraction is non-trivial.

Cross-References