Group Purchasing
Group Purchasing

Network Artifacts of Trusted Service Abuse

Network Artifacts of Trusted Service Abuse (PDF, 2.71MB)Published: 06 Aug, 2026

The ever-increasing adoption of trusted services and their interconnectivity with private resources provides new opportunities for malicious communication channels. Traditional indicators of compromise, such as IP/Domain reputation or beacon detection, are most effective against adversary-owned infrastructure but yield limited signals when communication channels run atop trusted services.

This study contrasts normal user traffic with known malicious activity to identify alternative indicators from four public C2 frameworks (DaaC2, DBC2, gdog, Callidus) operating on Dropbox, Discord, Gmail, and OneNote, using 51 packet captures (3 baselines, 6 automated browser tests and 6 framework tests per service).

Across four detection tiers, Reputation-based detection failed to identify any C2 channels; Beacon Detection was marginally viable when using clustering (2/4); Traffic Metadata was partially viable, with mixed results other than JA4 fingerprints (100% detection); and Traffic Patterns proved most viable, with both TLS session resumption near-zero (vs 22%+ for browser) and a 2.6x upload/download ratio gap (1.41 vs 0.55 means). Structural and behavioral indicators, such as TLS session resumption and JA4 fingerprinting, outperform reputation in detecting trusted service abuse.