
EV Certificate Minted for One Campaign Powers Three-Layer Evasion Chain
A Sectigo Extended Validation certificate issued to QUANTIS LOGIK LTD was procured, deployed, and burned within 39 days, signing two PE32 installers that masquerade as popular software downloads. The payloads combine active sandbox evasion with CloudFront domain-fronting to defeat static detection, dynamic analysis, and network inspection simultaneously across seven target regions.
Thirty-nine days. That is the total operational window separating the moment a Sectigo Extended Validation certificate was issued to an entity called QUANTIS LOGIK LTD and the moment the two PE32 installers it signed first appeared on VirusTotal. The certificate — serial number 00 86 51 B4 B7 A5 AF 08 DF 82 E5 FE 4E 5B 99 A8 18, thumbprint 1080D4CCFE6E5EE372CB3DB8686C37923A932AF5, issued 2026-04-22, used to sign both payloads on 2026-05-19, with the files submitted on 2026-06-01 — was not a…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read