{"id":11677,"date":"2026-03-25T12:59:59","date_gmt":"2026-03-25T12:59:59","guid":{"rendered":"https:\/\/events.aavar.org\/avar2025\/?page_id=11677"},"modified":"2026-03-25T12:59:59","modified_gmt":"2026-03-25T12:59:59","slug":"shadows-in-native-code-the-rise-of-aot-compilation-in-modern-net-malware","status":"publish","type":"page","link":"https:\/\/events.aavar.org\/avar2025\/index.php\/shadows-in-native-code-the-rise-of-aot-compilation-in-modern-net-malware\/","title":{"rendered":"Shadows in Native Code: The Rise of AOT Compilation in Modern .NET Malware"},"content":{"rendered":"\n[vc_row full_width=&#8221;stretch_row&#8221; el_class=&#8221;agenda-banner&#8221; el_id=&#8221;agenda_banner&#8221;] [vc_column]\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<div style=\"height:200px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"banner-text has-x-large-font-size wp-block-paragraph\">AGENDA<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\"><\/div>\n<\/div>\n\n\n\n<p>[\/vc_column] [\/vc_row]<\/p>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"agenda-link wp-block-paragraph\"><strong><a href=\"https:\/\/events.aavar.org\/avar2025\/index.php\/agenda\/\">&lt;&#8212; Back<\/a><\/strong><\/p>\n\n\n\n<p class=\"agenda-heading wp-block-paragraph\">Shadows in Native Code: The Rise of AOT Compilation in Modern .NET Malware<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The landscape of malware development is experiencing a significant shift as threat actors increasingly leverage Ahead of Time (AOT) compilation in .NET frameworks. Traditionally, .NET applications have been relatively straightforward to reverse engineer due to their intermediate language representation, which preserves substantial program structure and metadata. However, the growing adoption of AOT compilation\u2014which transforms .NET code directly into native machine code\u2014presents formidable new challenges for security researchers and malware analysts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Our preliminary research indicates that approximately 75% of .NET AOT samples identified in the wild demonstrate malicious intent, suggesting this technique has been rapidly embraced by threat actors. AOT compilation effectively eliminates the Microsoft Intermediate Language (MSIL) layer, forcing analysts to work directly with assembly code and significantly complicating the reverse engineering process. This technique serves as an emerging obfuscation strategy that requires minimal effort from malware authors while providing substantial protection against analysis.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This paper examines the technical characteristics of AOT-compiled malware, presents methodologies for identification and analysis of these samples, and explores the development of specialized tools to recover function signatures and type information. We demonstrate how traditional .NET analysis techniques fail against AOT-compiled binaries and propose new approaches combining static and dynamic analysis to overcome these limitations. Furthermore, we discuss the security implications of Microsoft&#8217;s continued enhancement of AOT capabilities in newer .NET versions, which inadvertently provides malware authors with increasingly sophisticated evasion techniques.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As AOT compilation becomes more accessible with each .NET release, understanding its security implications becomes critical for maintaining effective malware detection and analysis capabilities in the evolving threat landscape.<\/p>\n\n\n\n<div style=\"height:42px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\"><div class=\"wp-block-image is-resized is-style-rounded\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"500\" src=\"https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Sarang-Popat-Sonawane.png\" alt=\"\" class=\"wp-image-11678\" style=\"width:225px\" srcset=\"https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Sarang-Popat-Sonawane.png 500w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Sarang-Popat-Sonawane-300x300.png 300w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Sarang-Popat-Sonawane-150x150.png 150w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Sarang-Popat-Sonawane-200x200.png 200w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/figure>\n<\/div><\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66.66%\">\n<p class=\"speaker-heading wp-block-paragraph\"><strong><strong><strong><strong><strong>Sarang Popat Sonawane &#8211; Crowdstrike<\/strong><\/strong><\/strong><\/strong><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sarang Sonawane currently holds the role of Security Researcher within CrowdStrike&#8217;s Malware Research Team, boasting 9+ years of experience with a primary focus on reverse engineering.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In recognition of his expertise, he has presented at security conferences, including BlackHat MEA and AVAR. He also loves playing CTF challenges and has successfully completed the Flare-On 9 and 11 security challenges.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Beyond his dedication to cybersecurity, Sarang thrives on intellectual challenges in the malware analysis domain. When not dissecting malicious code, he passionately engages in cricket matches and eagerly explores new destinations, satisfying his adventurous spirit.<\/p>\n<\/div>\n<\/div>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>[vc_row full_width=&#8221;stretch_row&#8221; el_class=&#8221;agenda-banner&#8221; el_id=&#8221;agenda_banner&#8221;] [vc_column] AGENDA [\/vc_column] [\/vc_row] &lt;&#8212; Back Shadows in Native Code: The Rise of AOT Compilation in Modern .NET Malware The landscape of malware development is experiencing a significant shift as threat actors increasingly leverage Ahead of Time (AOT) compilation in .NET frameworks. Traditionally, .NET applications have been relatively straightforward to reverse engineer due to their intermediate<\/p>\n<div class=\"h10\"><\/div>\n<p><a class=\"more-link2\" href=\"https:\/\/events.aavar.org\/avar2025\/index.php\/shadows-in-native-code-the-rise-of-aot-compilation-in-modern-net-malware\/\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-11677","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages\/11677","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/comments?post=11677"}],"version-history":[{"count":1,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages\/11677\/revisions"}],"predecessor-version":[{"id":11679,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages\/11677\/revisions\/11679"}],"wp:attachment":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/media?parent=11677"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}