#elf64
ELF64 hello world | tuket
tuket.github.io
January 8, 2026 at 3:01 PM
This game is a single 13 KiB file that runs on Windows, Linux and in the Browser
This game is a single 13 KiB file that runs on Windows, Linux and in the Browser.
A Portable Executable (.EXE), ELF64 and HTML polyglot that runs natively on Windows, Linux and in the Browser.
iczelia.net
January 12, 2026 at 2:31 AM
This game is a single 13 KiB file that runs on Windows, Linux and in the Browser

#gamedev #gamedevelopment #indiedev
This game is a single 13 KiB file that runs on Windows, Linux and in the Browser.
A Portable Executable (.EXE), ELF64 and HTML polyglot that runs natively on Windows, Linux and in the Browser.
iczelia.net
January 12, 2026 at 11:35 AM
I made a DIR program, in my new programming language which complies in my new compiler, which produces a Linux elf64 binary.

14 lines, 665 bytes, I am very pleased. It is a start.

#programming #language #compilers #computers #hacker #nerd
June 27, 2026 at 1:17 AM
C89cc.sh – standalone C89/ELF64 compiler in pure portable shell

#HackerNews

<a href="https://gist.github.com/alganet/2b89c4368f8d23d033961d8a3deb5c19" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link" target="_blank" rel="noopener" data-link="bsky">https://gist.github.com/alganet/2b89c4368f8d23d033961d8a3deb5c19
April 3, 2026 at 2:41 AM
Finally ı released Biber :)

ELF32 / ELF64 parsing
PE32 / PE32+ parsing
32 / 64 bit detection
Headers, sections, symbols and relocations
PE imports and exports
Basic disassembler view

github:
github.com/hrasityilmaz...

#pe #windowsinternals #reverseengineering #systemsprogramming #opensource
June 2, 2026 at 10:18 AM
C89cc.sh – standalone C89/ELF64 compiler in pure portable shell

https://gist.github.com/alganet/2b89c4368f8d23d033961d8a3deb5c19
April 3, 2026 at 1:30 AM
structs in fasm are very epic
January 13, 2026 at 4:25 AM
Fixed the context-growing-to-large issue in my Debugger that uses AI for ELF64. I think this is a good use of Gen AI for educational purposes (which I believe it is actually useful for). This program takes a compiled binary and disassembles it into assembly code. This video shows setting registers
March 20, 2026 at 3:35 PM
also make-thotcrime is literally using GCC like it says GCC which is wild bcuz using ELF64 _AND_ GCC for bootstrapping is literally taking the two things you're at war with and then being like 'well what we think and what we need to bootstrap are allowed to be at odds'
February 27, 2025 at 8:16 PM
The dressmaking part is shitpacking the first however many bytes of the elf64 binary with the asm and C code and the rest is scala or erlang and coming up with application and implimentation design and overall architectures omg its the best part and having choice like using BSD as a base
February 3, 2025 at 3:34 AM
こんな記事があったとは!
私のほうは設計は知識がないので独自でやってる感じですね()
かなり器用貧乏かも

ブート:自作(UEFIアプリ、ELF64パーサ、BootInfo設計、ExitBootServices)
画面:GOPフレームバッファ + 自前フォント描画 + バックバッファ + ダーティ矩形
GDT/IDT/ページング:ディスクリプタ符号化自作
PIC:ICW1〜ICW4自作
シリアル:自作
割り込みハンドラ:naked asmスタブ自作
ツールチェイン:stable 1.97.1固定

という感じです!
July 21, 2026 at 12:37 PM
This game is a single 13 KiB file that runs on Windows, Linux and in the Browser.
https://iczelia.net/posts/snake-polyglot/
This game is a single 13 KiB file that runs on Windows, Linux and in the Browser.
A Portable Executable (.EXE), ELF64 and HTML polyglot that runs natively on Windows, Linux and in the Browser.
iczelia.net
January 12, 2026 at 3:40 PM
📢 ZAWOOO : ransomware Linux dédié aux NAS Synology avec chiffrement silencieux en deux étapes

📅 Source : RansomLook (ransomlook.io), rapport de rétro-ingénierie publié le 2026-08-29, basé sur l'analyse statique du binaire…

🟢 vérification factuelle haute
#ZAWOOO #ChiffrementSilencieux #Cyberveille
ZAWOOO : ransomware Linux dédié aux NAS Synology avec chiffrement silencieux en deux étapes
📅 Source : RansomLook (ransomlook.io), rapport de rétro-ingénierie publié le 2026-08-29, basé sur l'analyse statique du binaire SHA-256 33d3afddaa5710cdcc4e93a7bae8be010c19747fb53d85fcd54ef32056a1eb0b. ZAWOOO est un encrypteur Linux/ELF64 statique-pie conçu exclusivement pour les NAS Synology DSM.
cyberveille.ch
September 1, 2026 at 9:00 PM
I feel bad calling it a Fiwix fork at this point, because it's incompatible at a fundamental level. It uses the ELF64 binary format, has full 64 bit syscall table, no support for 32-bit anything. It even has extra syscalls Fiwix doesn't.
August 23, 2026 at 12:55 AM
Back to Aster (my toy OS), a raw binary bootloader with minimal FAT support now loads an ELF64 kernel (no GRUB). The kernel executes ELF64 binaries and includes an early shared library loader (for libc and libcore).
April 26, 2026 at 4:49 PM
April 5, 2026 at 1:53 PM
New SysUpdate Variant Malware Discovered and Tool Developed to Decrypt Encrypted Linux C2 Traffic
New SysUpdate Variant Malware Discovered and Tool Developed to Decrypt Encrypted Linux C2 Traffic
A new variant of the SysUpdate malware has emerged as a sophisticated threat targeting Linux systems with advanced command-and-control (C2) encryption capabilities. The malware was discovered during a Digital Forensics and Incident Response (DFIR) engagement when security teams detected the suspicious Linux binary in a client’s environment. This packed ELF64 executable uses an unknown obfuscated packer with no section header, making traditional analysis methods challenging. The threat disguises itself as a legitimate system service, and when executed without specific arguments, it performs reconnaissance by running the GNU/Linux ID command to gather system information before establishing encrypted network communications across multiple protocols. LevelBlue analysts identified strong indicators linking the sample to a new version of SysUpdate after conducting dynamic analysis and examining endpoint detection metrics. The researchers confirmed this attribution with high confidence through comprehensive reverse engineering efforts. The malware’s C++ codebase implements complex cryptographic routines that encrypt its C2 traffic, creating a significant obstacle for network-based detection and traffic analysis. In response to this challenge, cybersecurity researchers developed specialized tooling using the Unicorn Engine emulation framework to decrypt the malware’s encrypted communications without fully understanding the underlying encryption algorithm. LevelBlue researchers noted that the decryption tool was built during an active incident investigation, demonstrating rapid response capabilities in real-world scenarios. The technical approach involved extracting machine code bytes, global data structures, heap values, and CPU register states from the malware sample during runtime. Key generation (Source – LevelBlue) By emulating the malware’s key generation and encryption routines, analysts successfully decrypted intercepted C2 traffic and exposed the plaintext communications. Encrypted key data (Source – LevelBlue) The methodology relies on Binary Ninja for static analysis, GDB for dynamic debugging, and Rust-based Unicorn Engine bindings to emulate x86-64 assembly code without completely reverse engineering the complex cryptographic implementation. Decryption Tool Development and Methodology The decryption solution uses CPU emulation to leverage the malware’s own cryptographic functions against itself. Researchers created two separate emulators working in tandem: one for key generation that processes the hardcoded plaintext encryption key extracted from the malware’s heap memory, and another for decryption that processes 8-byte data blocks using XOR operations combined with an unknown encryption algorithm. Emulation layer (Source – LevelBlue) The emulation environment replicates the exact memory mappings from the malware’s process space, including stack addresses, heap structures, data segments containing cryptographic constants, and code segments with the encryption routines. This approach allows security teams to decrypt C2 traffic from any sample in this malware family by simply extracting the new encryption key from future variants. Organizations should deploy endpoint detection solutions capable of monitoring for packed ELF executables with suspicious system service behavior. Security teams should implement network traffic analysis to identify encrypted communications patterns, even when decryption is not immediately possible. Incident response procedures should include capabilities for rapid malware emulation and reverse engineering to develop custom decryption tools during active investigations. Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in  Google . The post New SysUpdate Variant Malware Discovered and Tool Developed to Decrypt Encrypted Linux C2 Traffic appeared first on Cyber Security News .
cybersecuritynews.com
February 18, 2026 at 3:39 PM
📰 C89cc.sh – standalone C89/ELF64 compiler in pure portable shell

💬 Exec: c89cc.sh single-file POSIX shell to x86 ELF. Sentiment: positive; vibe: impressed+pragmatic. 😏

https://news.ycombinator.com/item?id=47598413
April 3, 2026 at 2:00 AM
C89cc.sh – standalone C89/ELF64 compiler in pure portable shell | Discussion
c89cc.sh - standalone C89/ELF64 compiler in pure portable shell
c89cc.sh - standalone C89/ELF64 compiler in pure portable shell - c89cc.sh
gist.github.com
April 3, 2026 at 2:00 AM
Game is a single 13 KiB file that runs on Windows, Linux and in the Browser | Discussion
This game is a single 13 KiB file that runs on Windows, Linux and in the Browser.
A Portable Executable (.EXE), ELF64 and HTML polyglot that runs natively on Windows, Linux and in the Browser.
iczelia.net
January 11, 2026 at 10:40 PM
KnightCTF 2026 – KrackM3 Challenge Writeup

KrackM3 is a reverse engineering challenge that presents a Linux ELF64 binary implementing a custom cryptographic validation scheme. The binary verifies a 32-character flag using a sophisticated multi-layer cipher combining: Fisher-Yates S-Box generation…
KnightCTF 2026 – KrackM3 Challenge Writeup
KrackM3 is a reverse engineering challenge that presents a Linux ELF64 binary implementing a custom cryptographic validation scheme. The binary verifies a 32-character flag using a sophisticated multi-layer cipher combining: Fisher-Yates S-Box generation with xorshift PRNG A 256-byte random lookup table generated via xorshift64* algorithm FNV-1a inspired hash state updates with rotation operations 4-way parallel validation accumulators using OR-based error accumulation&hellip;
kore.one
January 23, 2026 at 8:02 AM