Bytecode Jiu-Jitsu: Choking Interpreters to Force Execution of Malicious Bytecode

Unknown

Black Hat USA 2024 · Day 1 · Briefing

This talk introduces a groundbreaking new code injection attack dubbed **Bytecode Jiu-Jitsu**. Presented by Toshinori and Yuto Otsuki, research scientists from NTT Security Holdings, this technique represents a significant evolution in evasion capabilities for malicious actors. Unlike traditional code injection methods that target native processes and inject machine code, Bytecode Jiu-Jitsu specifically focuses on **interpreters** and the manipulation of their internal **bytecode**.

Watch on YouTube