
EV Certificate Held 13 Months Before Signing Four Malicious Payloads
A Sectigo Extended Validation certificate issued to 'ORYON TECH LIMITED' sat dormant for over a year before batch-signing an MSI installer and three PE32 executables in a single April 2026 session. The signed bundle delivers Microleaves proxy agent and Legion adware while defeating sandbox analysis at up to 98% confidence, exposing a financially motivated campaign with a structured affiliate pay-per-install backend.
Four Windows executables and an MSI installer, all bearing a valid Sectigo Extended Validation code-signing certificate issued to a company called "ORYON TECH LIMITED," began circulating through cracked-software distribution channels in April 2026 — but the certificate that makes them look legitimate to Windows SmartScreen and most endpoint defences was acquired more than a year before the first payload ever appeared.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read