Skip to content

ktn1703/Vanish-Obfuscator

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

19 Commits
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation


 β–ˆβ–ˆβ–’   β–ˆβ–“ β–„β–„β–„       β–ˆβ–ˆβ–ˆβ–„    β–ˆ  β–ˆβ–ˆβ–“  β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ  β–ˆβ–ˆβ–‘ β–ˆβ–ˆ     β–„β–ˆβ–ˆβ–ˆβ–ˆβ–„   β–ˆβ–ˆβ–“     β–ˆ    β–ˆβ–ˆ  β–„β–„β–„β–„   
β–“β–ˆβ–ˆβ–‘   β–ˆβ–’β–’β–ˆβ–ˆβ–ˆβ–ˆβ–„     β–ˆβ–ˆ β–€β–ˆ   β–ˆ β–“β–ˆβ–ˆβ–’β–’β–ˆβ–ˆ    β–’ β–“β–ˆβ–ˆβ–‘ β–ˆβ–ˆβ–’   β–’β–ˆβ–ˆβ–€ β–€β–ˆ  β–“β–ˆβ–ˆβ–’     β–ˆβ–ˆ  β–“β–ˆβ–ˆβ–’β–“β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–„ 
 β–“β–ˆβ–ˆ  β–ˆβ–’β–‘β–’β–ˆβ–ˆ  β–€β–ˆβ–„  β–“β–ˆβ–ˆ  β–€β–ˆ β–ˆβ–ˆβ–’β–’β–ˆβ–ˆβ–’β–‘ β–“β–ˆβ–ˆβ–„   β–’β–ˆβ–ˆβ–€β–€β–ˆβ–ˆβ–‘   β–’β–“β–ˆ    β–„ β–’β–ˆβ–ˆβ–‘    β–“β–ˆβ–ˆ  β–’β–ˆβ–ˆβ–‘β–’β–ˆβ–ˆβ–’ β–„β–ˆβ–ˆ
  β–’β–ˆβ–ˆ β–ˆβ–‘β–‘β–‘β–ˆβ–ˆβ–„β–„β–„β–„β–ˆβ–ˆ β–“β–ˆβ–ˆβ–’  β–β–Œβ–ˆβ–ˆβ–’β–‘β–ˆβ–ˆβ–‘  β–’   β–ˆβ–ˆβ–’β–‘β–“β–ˆ β–‘β–ˆβ–ˆ    β–’β–“β–“β–„ β–„β–ˆβ–ˆβ–’β–’β–ˆβ–ˆβ–‘    β–“β–“β–ˆ  β–‘β–ˆβ–ˆβ–‘β–’β–ˆβ–ˆβ–‘β–ˆβ–€  
   β–’β–€β–ˆβ–‘   β–“β–ˆ   β–“β–ˆβ–ˆβ–’β–’β–ˆβ–ˆβ–‘   β–“β–ˆβ–ˆβ–‘β–‘β–ˆβ–ˆβ–‘β–’β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–’β–’β–‘β–“β–ˆβ–’β–‘β–ˆβ–ˆβ–“   β–’ β–“β–ˆβ–ˆβ–ˆβ–€ β–‘β–‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–’β–’β–’β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–“ β–‘β–“β–ˆ  β–€β–ˆβ–“
   β–‘ ▐░   β–’β–’   β–“β–’β–ˆβ–‘β–‘ β–’β–‘   β–’ β–’ β–‘β–“  β–’ β–’β–“β–’ β–’ β–‘ β–’ β–‘β–‘β–’β–‘β–’   β–‘ β–‘β–’ β–’  β–‘β–‘ β–’β–‘β–“  β–‘β–‘β–’β–“β–’ β–’ β–’ β–‘β–’β–“β–ˆβ–ˆβ–ˆβ–€β–’
   β–‘ β–‘β–‘    β–’   β–’β–’ β–‘β–‘ β–‘β–‘   β–‘ β–’β–‘ β–’ β–‘β–‘ β–‘β–’  β–‘ β–‘ β–’ β–‘β–’β–‘ β–‘     β–‘  β–’   β–‘ β–‘ β–’  β–‘β–‘β–‘β–’β–‘ β–‘ β–‘ β–’β–‘β–’   β–‘ 
     β–‘β–‘    β–‘   β–’      β–‘   β–‘ β–‘  β–’ β–‘β–‘  β–‘  β–‘   β–‘  β–‘β–‘ β–‘   β–‘          β–‘ β–‘    β–‘β–‘β–‘ β–‘ β–‘  β–‘    β–‘ 
      β–‘        β–‘  β–‘         β–‘  β–‘        β–‘   β–‘  β–‘  β–‘   β–‘ β–‘          β–‘  β–‘   β–‘      β–‘      
     β–‘                                                β–‘                               β–‘                                               

VANISH v1.0

Python Obfuscator | Next-Gen Protection

Author: KTN (TrΖ°Ζ‘ng NhαΊ­t BαΊ£o Nam)
Version: 1.0
Status: Public Release (Outdated)
GitHub: github.com/ktn1703/Vanish-Obfuscator

Discord: ktn1703 or ktn0755


"Don't Read This Code Because You Will Be Dizzy By My Magic!"


⚠️ Disclaimer

This is an outdated version of Vanish, released to the public.
A more powerful successor has already been built β€” this version is no longer maintained.
Use at your own discretion. For educational and authorized security research purposes only.


Overview

Vanish v1.0 is a military-grade Python obfuscator that transforms readable Python source code into virtually untraceable, tamper-proof bytecode. It combines a custom Bytecode Virtual Machine (BVM) with multi-layer cryptographic encryption and advanced anti-analysis techniques to create outputs that resist static analysis, decompilation, debugging, and reverse engineering.


Features

πŸ”’ BVM Engine (Bytecode Virtual Machine)

A fully custom virtual machine that lifts Python bytecode into a proprietary format. The original opcodes are scrambled, encrypted, and reconstructed at runtime β€” making traditional decompilers completely useless.

πŸ›‘οΈ 5-Layer Cryptographic Protection

Every payload is protected by five nested encryption layers, each using independently derived keys via HKDF-SHA256:

Layer Algorithm Purpose
1 Byte Shuffle Deterministic permutation of the entire payload
2 XOR-Shift Stream Pseudo-random stream cipher with 64-bit state
3 ChaCha20 Authenticated stream cipher (10-round)
4 AES-256-GCM Authenticated encryption with GHASH integrity
5 zlib Compression Maximum compression (level 9) before encryption

🧬 AST-Level Obfuscation

  • String Encryption β€” 5 different XOR-based schemes (positional, reversed, split, RC4-like, modular addition)
  • Integer Obfuscation β€” MBA (Mixed Boolean-Arithmetic) expressions, XOR decomposition, opaque predicates, trilinear transforms
  • Variable Renaming β€” Confusable character pool (I, l, 1, O, 0) for maximum confusion
  • Control Flow Flattening β€” Converts sequential logic into a state-machine while/switch pattern
  • Junk Code Injection β€” 14–22 dead functions with opaque predicates and try/except noise

πŸ” Anti-Analysis Arsenal

Protection What It Blocks
Anti-Debug pdb, debugpy, pydevd, winpdb, frida, VS Code / PyCharm debuggers
Anti-Hook Function hooking, import interception, monkey-patching
Anti-Frame Stack inspection, frame walking, file descriptor monitoring
Anti-VM VMware, VirtualBox, QEMU, Hyper-V, Docker, Parallels, KVM
Anti-Proxy mitmproxy, Charles, Fiddler, Burp Suite, HTTP Toolkit
Anti-Decompiler Crashes pycdc, recursion bombs, corrupted marshal data
Tamper Guard SHA-256 integrity checks, header validation, burn-on-modify
Hardware Binding Optional machine-locked execution (HW fingerprint)
Python Version Lock Optional lock to specific Python minor version

🧊 Self-Destruct Mechanism

If any tampering, debugging, or hooking is detected, the program immediately burns β€” consuming all CPU cores, spawning infinite loops, and force-killing itself via TerminateProcess / os._exit(137).


Architecture

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚                   SOURCE CODE                   β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                       β”‚
          β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
          β”‚    AST Transformation   β”‚
          β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚
          β”‚  β”‚  Rename Variables  β”‚ β”‚
          β”‚  β”‚  Encrypt Strings   β”‚ β”‚
          β”‚  β”‚  Obfuscate Ints    β”‚ β”‚
          β”‚  β”‚  Inject Junk Code  β”‚ β”‚
          β”‚  β”‚  Flatten Control   β”‚ β”‚
          β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚
          β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                       β”‚
          β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
          β”‚   BVM Engine (bvm.py)   β”‚
          β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚
          β”‚  β”‚  Opcode Scramble   β”‚ β”‚
          β”‚  β”‚  Const Encryption  β”‚ β”‚
          β”‚  β”‚  Custom Packaging  β”‚ β”‚
          β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚
          β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                       β”‚
          β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
          β”‚  5-Layer Crypto Chain   β”‚
          β”‚                         β”‚
          β”‚  Shuffle β†’ XOR β†’ ChaCha β”‚
          β”‚  β†’ AES-GCM β†’ Compress   β”‚
          β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                       β”‚
          β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
          β”‚   Loader Generation     β”‚
          β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚
          β”‚  β”‚  Anti-Debug        β”‚ β”‚
          β”‚  β”‚  Anti-Hook/VM      β”‚ β”‚
          β”‚  β”‚  Tamper Guards     β”‚ β”‚
          β”‚  β”‚  Self-Destruct     β”‚ β”‚
          β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚
          β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                       β”‚
          β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
          β”‚     OUTPUT (.py)        β”‚
          β”‚   Obfuscated Payload    β”‚
          β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Installation

Requirements

  • Python 3.8+
  • Optional: pystyle (for colored terminal output)

Setup

git clone https://github.com/ktn1703/Vanish-Obfuscator.git
cd Vanish-Obfuscator
pip install pystyle  # optional

Usage

Interactive Mode

python aevanish.py

The tool will guide you through a beautiful terminal interface with gradient banners and step-by-step prompts.

Command-Line Mode

python aevanish.py --file input.py --output output.py

CLI Options

Flag Description
--file, -f Input Python file path
--output, -o Output file path (default: input_obf.py)
--no-anti-debug Disable anti-debug protection
--no-anti-hook Disable anti-hook protection
--no-anti-frame Disable anti-frame / GC wipe
--no-junk Disable junk code injection
--hw-bind Enable hardware-key binding
--py-lock Lock to current Python version
--no-anti-vm Disable anti-VM/sandbox detection
--no-anti-proxy Disable anti-proxy/MITM detection
--no-anti-httptoolkit Disable anti-HTTP Toolkit detection
--no-anti-pydc Disable anti-decompiler crash
--silent No output
--banner Show banner

Example

python aevanish.py --file my_script.py --output protected.py --hw-bind

Protection Summary

When you run Vanish, your output file will contain:

╔══════════════════════════════════════════════════════╗
β•‘  ALWAYS ON                                           β•‘
β•‘  β”œβ”€β”€ 5-Layer AES-GCM + ChaCha20 + XOR + Shuffle      β•‘
β•‘  β”œβ”€β”€ HKDF-SHA256 Key Derivation                      β•‘
β•‘  β”œβ”€β”€ BVM v8 Poly-Opcode Engine                       β•‘
β•‘  β”œβ”€β”€ MBA Integer Obfuscation                         β•‘
β•‘  β”œβ”€β”€ Multi-Scheme String Encryption                  β•‘
β•‘  └── Tamper-Burn Integrity Guard                     β•‘
β•‘                                                      β•‘
β•‘  CONFIGURABLE (all ON by default)                    β•‘
β•‘  β”œβ”€β”€ Anti-Debug Detection                            β•‘
β•‘  β”œβ”€β”€ Anti-Hook / Anti-Import                         β•‘
β•‘  β”œβ”€β”€ Anti-Frame / Stack Inspection                   β•‘
β•‘  β”œβ”€β”€ Anti-VM / Sandbox Evasion                       β•‘
β•‘  β”œβ”€β”€ Anti-Proxy / MITM Detection                     β•‘
β•‘  β”œβ”€β”€ Anti-HTTP Toolkit                               β•‘
β•‘  β”œβ”€β”€ Anti-Decompiler Crash (pycdc)                   β•‘
β•‘  β”œβ”€β”€ Junk Code Injection (14-22 dead functions)      β•‘
β•‘  β”œβ”€β”€ Control Flow Flattening                         β•‘
β•‘  β”œβ”€β”€ Hardware Binding (optional)                     β•‘
β•‘  └── Python Version Lock (optional)                  β•‘
β•šβ•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•

File Structure

β”œβ”€β”€ aevanish.py          # Main obfuscator (CLI, AST transforms, loader builder)
β”œβ”€β”€ bvm_engine.py        # BVM bytecode virtual machine engine
└── README.md            # This file

How It Works

  1. Parse β€” Source is parsed into an AST (Abstract Syntax Tree)
  2. Transform β€” Variables renamed, strings encrypted (5 schemes), integers obfuscated (MBA expressions), junk code injected, control flow flattened
  3. Lift β€” Transformed AST is compiled and lifted into BVM's custom binary format with opcode scrambling
  4. Encrypt β€” The BVM payload passes through 5 nested encryption layers with independently derived keys
  5. Wrap β€” A self-protecting loader is generated containing anti-debug, anti-hook, tamper checks, and a self-destruct mechanism
  6. Output β€” A single .py file that runs independently with zero dependencies

Technical Details

Crypto Implementation

All cryptographic primitives are implemented from scratch in pure Python with zero external dependencies:

  • AES-256-GCM β€” Full S-Box, key expansion, GF(2^128) multiplication, GHASH
  • ChaCha20 β€” Quarter-round operations, 10-round block function
  • HKDF β€” Extract-then-expand with SHA-256
  • XOR-Shift β€” 64-bit state PRNG with configurable seed
  • Byte Shuffle β€” Deterministic Fisher-Yates with SHA-256 seeded RNG

BVM Engine

  • Custom opcode scrambling with reverse-map restoration
  • XOR-based code encryption with 64-bit seed
  • Full constant pool serialization (ints, floats, complex, strings, bytes, tuples, lists, dicts, sets, code objects)
  • Multi-version CodeType reconstruction for Python 3.8–3.12+

Version History

Version Status
v1.0 This release β€” public, outdated
v2.0+ Private β€” significantly more powerful

License

Here


Built by KTN β€” 2026

Releases

No releases published

Packages

 
 
 

Contributors

Languages