

I found this on a Reddit thread, hopefully this gets you on the right track:
“I think checking for the GOG sp. z o.o signature is good enough but checking with AV can also be good. If the exe file has been tampered with, then the digital signature would be invalidated. If the bin files have been tampered with, then running the untampered exe will give the error: https://imgur.com/a/9e5lIZ7. They should be legit as long as it has the legit GOG digital signature. GOG has different signatures for older and newer games btw. You can use https://github.com/hippie68/gogcheck to check the games.”
This is not new. Over 20 years ago, Marines with chronic razor bumps would have to head to the medic to get a waiver for inspections. A couple of them had such a bad case, their waver would allow them to keep a very tightly trimmed beard for their entire time.