Tauri App Flagged as Trojan: How I Found the Culprit
A Windows Roblox account management application was flagged as a trojan by Microsoft due to an AI machine learning verdict, leading the developer to track down the encryption library issue using bisection.

Stock photo for illustration only, not from the actual event
- The Roblox Account Manager app was flagged by Microsoft as Trojan:Win32/Wacatac.B!ml via a machine learning model.
- The developer tracked down the problematic commit using Git Bisect combined with the VirusTotal API.
- The trigger was traced to the use of libsodium via sodiumoxide, which heuristics associated with malware behavior.
- The issue was resolved by migrating to pure-Rust RustCrypto crates and optimizing compilation profiles in Cargo.toml.
A desktop application developer faced a puzzling issue when their utility designed for managing Roblox accounts was flagged by Microsoft security systems as Trojan:Win32/Wacatac.B!ml, despite the source code having no malicious intent. The application, known as RAM or Roblox Account Manager, is built using Rust, Tauri 2, and React to handle multiple gaming sessions simultaneously.
Because the app handles session cookies, spawns background processes, brings game windows to the foreground, and simulates user input, it naturally exhibits characteristics that heuristic engines scrutinize closely. After a routine release, Windows began issuing warnings about the executable file, and VirusTotal reported a 1/75 detection rate pointing specifically to a machine learning verdict rather than a known signature match.

Stock photo for illustration only, not from the actual event
Initial assumptions suggested the behavior profile remained consistent and the model had simply shifted its parameters. However, by utilizing Git Bisect alongside the VirusTotal API—which permits free requests at a rate of 4 per minute and 500 per day—a systematic search was conducted using a script to hash files, check existing reports, and upload new builds.
The investigation revealed that the first flagged commit integrated account file encryption using sodiumoxide, the Rust bindings for libsodium. Statically linking the optimized native cryptographic C library inside an application handling credentials created a pattern resembling ransomware and credential stealers in the eyes of the classifier, even though libsodium itself was completely secure.
This scenario highlights the growing complexity developers face as security scanners increasingly rely on machine learning models. Behavioral analysis models can flag legitimate software combinations simply due to statistical similarities with malicious tooling, requiring precise diagnostic workflows like bisection to isolate false positives.
To replace the library without breaking existing user files stored on disk, the developer transitioned to pure-Rust RustCrypto crates, replicating every libsodium parameter precisely. Validation tests ensured that payloads encrypted with the legacy implementation could be decrypted accurately by the new codebase.
A performance bottleneck arose because pure-Rust Argon2 in debug builds took 5.4 seconds per derivation compared to 0.3 seconds when optimized. By configuring Cargo.toml to optimize dependencies even during development builds, the test suite execution time dropped from 230 seconds down to 41 seconds, surpassing the previous performance levels.
Source: Dev.to
Found something wrong in this article? Report an issue with this article
Comments
Leave a Comment