Evading Machine Learning Based Detections

September 16, 2026 · Fabian Mosch - @ShitSecure · Evasion, Packer, Loader, Machine Learning

In my x33fcon talk The Art of Evasion, I presented general Packer/Loader explanations as well as what machine-learning-based detections are about and how to bypass them. This blog post is the companion to that talk and also introduces the RustPack version 1.7 features that cover ML evasion by default.

The Packer/Loader Architecture and Minimum Needed Features

When we talk about the architecture of a Packer in the malware development field, it usually consists of two main components:

  1. The Packer code
  2. The Loader code

The Packer can be used by an operator with various input arguments to enable optional features. It typically encrypts or encodes an input payload, generates the “Loader code” and then compiles it to produce an executable, DLL or other output payload. That output payload executes the original input from memory in an OPSEC-safe way after decrypting or decoding it.