Recon 2026

Mark Lim

Mark Lim has been in the cybersecurity domain for close to 20 years. Currently, he is a principal malware reverse engineer at Palo Alto Networks. He focuses on analysing malware samples and developing detection mechanisms. Mark constantly looks for opportunities to improve his reverse engineering skills by sharing experiences with others. Mark believes every piece of binary contains a story waiting for a reverse engineer to tell it. Before working at Palo Alto Networks he spent 10 years as a blue teamer at the Singapore government. Mark has spoken at VirusBulletin 2023, 2024 and 2025 and JSAC 2026.


Session

06-21
13:00
180min
Orchestrating Chaos: Defeating Guloader's VEH and Obfuscation with Unicorn
Mark Lim

Standard sandboxes and automated scanners fall short when faced with the modern state of Guloader. Its reliance on Vectored Exception Handling (VEH) to redirect control flow through intentional exceptions creates a "black box" for traditional debuggers and linear disassemblers. This 3 hour workshop bypasses the basics and dives straight into the heavy lifting of modern malware deobfuscation.

We will perform a deep-dive dissection of a multi-stage infection chain, moving rapidly through PowerShell loaders into the core of the matter: multi-layered shellcode. Participants will reverse-engineer the "exception soup" of Guloader, mapping out how it uses various CPU instructions and a custom handler to mask its code flow.

The highlight of the session is a transition from manual analysis to programmatic automation. We will leverage the Unicorn emulator framework to build a custom configuration extractor capable of reconstructing non-contiguous encrypted payloads that stay hidden from static analysis.

Soprano B