PyArmor Runtime Obfuscation
PyArmor is a Python obfuscation tool that encrypts Python source code or bytecode and bundles a C-extension runtime (pyarmor_runtime.pyd on Windows) to decrypt and execute at load time. It is commonly used to protect Python payloads packed with PyInstaller.
Technique Details
- Encryption: Python modules are AES-encrypted and wrapped in a C-extension loader. The decryption key is derived at runtime from hardware fingerprints or a hardcoded license.
- Anti-tamper: The C-extension runtime verifies checksums of the protected scripts; modification causes silent failure.
- Import hook: Replaces the standard Python import mechanism with a custom
__import__hook that decrypts modules on first access. - String protection: Literal strings in the Python source are encrypted at rest and decrypted at runtime.
Detection
- Presence of
pyarmor_runtime_000000\pyarmor_runtime.pydin the PyInstaller TOC or extracted_MEI*temp directory. pyarmor_runtime_000000string in the binary overlay.- FLOSS and other string-decoding tools return only boilerplate; no plaintext C2, URLs, or configuration strings.
Limitations for Analysts
- Static string extraction is largely defeated.
- Dynamic analysis requires running the sample (or attaching a debugger to the Python process after the runtime decrypts).
- Memory dumps of the running process contain decrypted scripts but extraction is non-trivial.
Cross-References
- clickfix — family observed using PyArmor + PyInstaller
- python-packed-payload — concept page for PyInstaller-delivered threats