Skip to content
Obfuscationintermediate

Dead Code & Junk Insertion

No-op and garbage instruction sequences plus misaligned junk bytes are inserted to bloat the code and desynchronize linear-sweep disassemblers, hiding the real instruction stream.

Dead-code and junk insertion pads a function with instructions that have no effect on its result, and sprinkles misaligned junk bytes into the stream — typically right after an unconditional jump, where the bytes are never executed but a linear-sweep disassembler will still try to decode them. The goal is to inflate the binary and break naive disassembly so the real logic is buried.

How it works

Dead code is semantically inert: arithmetic that cancels out, writes to dead registers, or nop-equivalents. The anti-disassembly trick places a jmp over a byte that is the start of a multi-byte instruction; a linear sweep mis-decodes from that byte and desynchronizes from the real instructions that follow.

asm
    xor  eax, eax        ; junk: dead store, eax overwritten below
    add  eax, ebx
    sub  eax, ebx        ; junk: net effect zero
    jmp  short real      ; unconditional jump...
    db   0xE8            ; ...over a junk byte that starts a fake CALL
real:
    mov  [rdi], rcx      ; the real instruction (a linear sweep desyncs here)

Detection & bypass

  • Static — In IDA/Ghidra junk regions show up as runs of obviously useless arithmetic (add/sub pairs, xor reg,reg before an unconditional overwrite), unreachable bytes flagged as data, or red "bad instruction" markers where the sweep desynced after a jmp. Switch the view to recursive-descent and the fake byte resolves away.
  • Dynamic — Emulate the function (Unicorn/Qiling) so only the live path executes; the trace shows the real instruction sequence and skips the junk byte entirely. Comparing the static listing to the executed trace pinpoints inserted garbage.
  • Patch / simplify — Force-decode at the correct boundary (undefine bytes, re-create code), then apply peephole dead-store/cancellation elimination to drop the inert instructions and leave the live path.
  • Tools — IDA/Ghidra recursive-descent disassembly, Unicorn and Qiling for emulation, Capstone for custom decoding, and peephole simplification scripts.
Votes

Comments(0)