
EV Certificate Issued to ORYON TECH LIMITED Signs Four Malicious Payloads in Single Batch
A single Extended Validation code-signing certificate tied to ORYON TECH LIMITED was used to simultaneously legitimise four malicious files — branded as 'AW Manager / Windows Manager' — in a coordinated signing event on 23 April 2026. The Microleaves/Jatif/Legion payload bundle pairs EV-based trust suppression with CPU-name and debugger-detection evasion that returned clean verdicts from two sandbox environments despite AV detection ratios reaching 44/76. A three-layer C2 infrastructure linked by shared Iceland-based WHOIS registrant fingerprints spans Namecheap-hosted servers, Cloudflare-proxied .info domains, and freshly provisioned Let's Encrypt nodes.
At 8:36 on the morning of 23 April 2026, an operator pressed the metaphorical button on a code-signing ceremony that bound four distinct malicious payloads to a single Extended Validation certificate — a credential class that Sectigo's issuance process requires to be anchored to a verified legal entity. The entity named on that certificate is ORYON TECH LIMITED.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read