Ophion: The Hypervisor That Lies to the Clock

How a stealth Type-2 hypervisor uses micro-architectural time compensation and private memory boundaries to subsume Windows and evade modern anti-cheats.

7 min read • View on GitHub • More from zer0condition

A dense mechanical pocket watch with an open back, showing a microscopic manipulator holding back a core gear. This illustrates Ophion's deliberate manipulation of CPU timing.
Ophion defeats timing attacks by actively intercepting and spoofing the processor's time-stamp counter.

Intel VT-x Type-2 hypervisor that virtualizes an already running Windows system. Designed for stealth: passes common hypervisor detection checks and works with **EAC/BE/AVs out of the box.**

zer0condition, Author/Maintainer · Ophion README
Key Takeaways

The Stopwatch Problem

Modern anti-cheats operate at the lowest levels of the Windows kernel. When they look for hidden hypervisors, they do not search for files or memory signatures. They simply measure time. By executing a sensitive instruction like CPUID, the guest operating system forces the CPU to transition into hypervisor mode. This transition is called a VM-exit.

A VM-exit takes thousands of clock cycles to process. Security software records the exact timestamp before and after the instruction bounds. If the execution takes abnormally long, the anti-cheat concludes a hypervisor is present and immediately crashes the game. To survive, a hypervisor cannot just be invisible. It must counterfeit the latency of bare-metal hardware.

The trap-and-compensate sequence Ophion uses to spoof the Time Stamp Counter.

The Trap-and-Compensate Engine

Ophion solves the stopwatch problem using a dynamic trap-and-compensate strategy. When an instruction triggers a VM-exit, the engine calculates the exact computational cost of its own intervention. It then arms a flag to intercept the very next time-stamp counter request.

When the anti-cheat asks the CPU for the current time via the RDTSC instruction, Ophion steps in. It takes the true hardware time, subtracts the exact microsecond overhead of the previous VM-exit, and passes the spoofed value back to the guest. The execution appears perfectly native.

Editorial portrait of zer0condition

Building a Private Universe

A hypervisor that subsumes an active OS cannot trust the kernel it sits beneath. Aggressive security drivers often intentionally corrupt system Page Table Entries to probe for hidden virtualization layers. If a naive hypervisor relies on the guest's memory structures, it will crash the machine.

Ophion neutralizes this threat by deep-copying the critical kernel page tables. It establishes a private Host CR3, alongside a private Global Descriptor Table and Interrupt Descriptor Table. This creates a ghost version of the kernel that only exists when the CPU is in VMX-root mode. The hypervisor maintains perfect state regardless of what the guest OS attempts to corrupt.

A cross-section of a two-story room. The top floor is chaotic with spilled ink, while the bottom floor is a pristine, identical reflection separated by thick glass. This represents Ophion's isolated Host CR3 memory space.
By copying kernel page tables into a private space, Ophion isolates itself from the chaotic and potentially hostile guest OS.

The Turn-Key Ghost

The open-source hypervisor landscape is split into two distinct camps. On one side are educational reference models like SimpleVisor. They are excellent learning tools but lack stealth features, making them instantly detectable by security software. On the other side are heavy research tools like DHypervisor, which require massive custom coding to hide effectively.

Ophion occupies a unique niche. It implements complex Intel manual requirements that educational tools skip, providing a stable, invisible foundation out of the box. It is a purpose-built platform for developers who need extreme stealth without writing thousands of lines of custom evasion logic.

HypervisorPrimary FocusOut-of-the-box StealthTSC Mitigation
OphionEvasion & Game HackingYesDynamic Compensation
DHypervisorAdvanced ResearchNoManual Implementation Required
SimpleVisorEducational ReferenceNoNone