Selective bytecode virtualization
Moves eligible sensitive methods into a diversified virtual instruction set, raising the effort needed to understand critical logic.
Layered protection that turns readable Java bytecode into a costly reverse-engineering problem—without changing how your customers run it.
One clear license · CLI + desktop GUI · Java 21 tooling
Oreo combines complementary transformations so attackers have to untangle names, data and execution—not just run one decompiler.
Moves eligible sensitive methods into a diversified virtual instruction set, raising the effort needed to understand critical logic.
Reshapes branches with opaque predicates, fake paths and optional state-machine techniques.
Removes useful plaintext from static inspection with per-class keys and AES, XOR or mixed modes.
Transforms packages, classes, methods and fields while conservatively preserving framework-sensitive contracts.
Purpose-built handling for records, lambdas, ServiceLoader, serialization, modules and Minecraft plugin metadata.
Verifies transformed bytecode and refuses to publish partial output when a protection step fails.
public boolean validateLicense(Key key) {
String secret = "production-secret";
return key.verify(secret);
}龘.ᚠ(oreo.v.x1ypjlca)
0x2C 0x71 0xA8 0x09
VM_DISPATCH → encrypted payloadHonest security: no client-side protection is unbreakable. Oreo raises attacker time, expertise and cost while preserving legitimate use.
Use the desktop GUI or point the CLI at your compiled application.
Start with a preset, then add keep rules for public APIs and reflective frameworks.
Oreo writes an atomic protected output and checks its bytecode before success.
OreoObfuscator Elite gives you every protection layer, the CLI and the desktop GUI for one year.
Get Elite — €200 / year →One-time annual payment. Instant account delivery after verified payment.