Borrowed Trust: A Detection Engineering Analysis of Three Concurrent Signed-Binary Sideload Campaigns, August 2026
Abstract
Report. Saluca Labs threat research. Defensive use only. In the first ten days of August 2026, three separate campaigns distributing malicious VPN software were in public circulation simultaneously, each reported by a different vendor about a different investigation. This paper answers the question none of the individual reports set out to answer: is this three detection problems or one? The campaigns are the BoryptGrab-lineage infostealer distributed through approximately 292 brand-impersonation GitHub repositories (Arctic Wolf); the QuickFox VPN supply chain compromise delivering the FDMTP implant, which persisted inside a signed vendor installer for roughly a year (Fortinet FortiGuard Labs); and the "Free VPN for PC" GitHub repository delivering Lumma Stealer (CYFIRMA). Two of the three share a single execution primitive, which the paper names borrowed trust: the process that executes is legitimate, correctly signed, and behaving exactly as designed, while the malicious code is something that process resolves at runtime. A signature authenticates the container; it asserts nothing about what the container loads after it starts. The same inversion appears in the delivery chain, where a github.io redirect is consumed as though it certified a destination GitHub never inspected. Crucially, none of the trusted parties did anything wrong, so there is no defect to patch and the pattern will outlive these three campaigns. The paper states explicitly where the synthesis is weaker: the third campaign is a partial case whose first stage borrows nothing. Detections are ranked on survival under infrastructure rotation, because the largest campaign regenerates its payload roughly every sixty seconds and is designed to defeat conventional indicator sharing. Four detections survive rotation entirely and are argued as the tier-one set. Section 5 is the ledger of what this class makes undetectable, and it is the section the individual vendor reports could not contain. Hash-based coverage is close to meaningless when the archive is rebuilt per request. Signature-based allowlisting fails by construction, in both directions, because the signatures are not lying. A clean endpoint sweep is weak evidence for two opposite reasons: one campaign installs no persistence at all and leaves nothing behind, while the other only implants hosts running one of 26 named applications, so a quiet host may be untouched and fully exposed at the same time. For that campaign the correct control is a software inventory check against the affected version range, not a hunt for implant artifacts. None of the three campaigns was surfaced by a victim's own detection stack. All three were found by threat researchers. That observation recurs across this series and has not yet failed to hold. The companion package at saluca-labs/borrowed-trust-detections (Apache-2.0) ships 22 Sigma rules, 12 YARA rules, 15 Defender XDR / Sentinel KQL queries, 16 Splunk SPL searches, 24 Suricata rules, two read-only PowerShell hunt scripts, and a consolidated indicator set. Validation status is published alongside the content: the YARA and Sigma packs were compiled and parsed with reproduction scripts included, the PowerShell executes, and the KQL, SPL and Suricata content was authored against published schemas but not executed. Limits are stated plainly: no victim forensic artifacts, no independent verification, no samples analysed by the authors, all ATT&CK mappings inferred rather than vendor-supplied, and attribution repeated as other researchers' assessment rather than asserted as fact.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.