
One EV Certificate Signs Four Files, Fools Every Sandbox
A single valid Sectigo EV code-signing chain issued to 'ORYON TECH LIMITED' covers a loader, updater, installer, and MSI payload in an adware install chain — keeping behavioural sandboxes reporting them clean while 24 to 44 of roughly 75 static AV engines flag each file malicious.
Four separate binaries — a loader, an updater, a secondary installer, and an MSI payload — all carry the identical Sectigo EV code-signing chain issued to "ORYON TECH LIMITED," and that shared, currently valid certificate is functioning as an active evasion layer rather than a simple trust marker. Static antivirus engines are not fooled: 24 to 44 of roughly 75 to 76 engines flag each file as malicious.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read