FILEMembers
FILE

EV Certificate Held 13 Months Before Signing Four Malicious Payloads

A Sectigo Extended Validation certificate issued to 'ORYON TECH LIMITED' sat dormant for over a year before batch-signing an MSI installer and three PE32 executables in a single April 2026 session. The signed bundle delivers Microleaves proxy agent and Legion adware while defeating sandbox analysis at up to 98% confidence, exposing a financially motivated campaign with a structured affiliate pay-per-install backend.

Jun 26, 2026, 02:43 (UTC+9)Last seenJun 26, 2026Severity74ByCTX TeamIOC39MITRE29RegionsSR

Four Windows executables and an MSI installer, all bearing a valid Sectigo Extended Validation code-signing certificate issued to a company called "ORYON TECH LIMITED," began circulating through cracked-software distribution channels in April 2026 — but the certificate that makes them look legitimate to Windows SmartScreen and most endpoint defences was acquired more than a year before the first payload ever appeared.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence