Researcher Built a Canary Executable to Spy on VirusTotal Sandboxes

A developer created a Rust-based executable with a fake identity — dubbed 'ZeroToken Engine' — and submitted it to VirusTotal to observe the analysis environments that ran it. The program collected metadata such as OS version, CPU and memory specs, uptime, hostname, and running process names, then reported findings via DNS heartbeats and HTTPS dossiers to the researcher's own infrastructure. It used two reporting channels: compact encoded DNS lookups and fuller CBOR-formatted HTTPS payloads, each tagged with a random eight-byte run ID. The experiment captured 353 event rows across 21 run IDs over a roughly five-hour window on September 12, 2026. The researcher noted that the binary installed nothing, harvested no credentials or documents, and intentionally disclosed the canary's true behavior in the project's README alongside its cover identity claims.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in