Yugami (歪み,"distortion") is a x64 binary packer written in Rust. It encrypts PE executables using ChaCha20 stream cipher with page-level key derivation and performs just-in-time page decryption at runtime.
Build:
cargo build --release --workspacePack an executable:
cargo run --release --bin packer -- --path path/to/target.exeOutputs packed.exe in the current directory.
- Parse PE headers and map sections to memory.
- Generate 256-bit random base key.
- Pad payload to 4KB page boundaries.
- Derive per-page keys using BLAKE3.
- Encrypt each page with ChaCha20.
- Append encrypted payload + metadata as overlay.
- Payload loaded into memory with PAGE_NOACCESS protection.
- Page fault exception triggered on first access.
- Page index derived from faulting address.
- Derive page key using BLAKE3 with page index.
- Update page protection to PAGE_READWRITE.
- Decrypt page using ChaCha20 with derived key.
- Update page protection back to original.
- Add page to LRU cache (max 256 pages).
- If LRU full, re-encrypt and protect evicted page as PAGE_NOACCESS.
- Return from exception handler, execution resumes.