APTMembers
APT

One EV Certificate Signs Four Files, Fools Every Sandbox

A single valid Sectigo EV code-signing chain issued to 'ORYON TECH LIMITED' covers a loader, updater, installer, and MSI payload in an adware install chain — keeping behavioural sandboxes reporting them clean while 24 to 44 of roughly 75 static AV engines flag each file malicious.

Aug 19, 2026, 06:34 (UTC+9)Last seenAug 19, 2026Severity82ByCTX TeamActorPatchworkChinastratsIOC41MITRE49RegionsIN

Four separate binaries — a loader, an updater, a secondary installer, and an MSI payload — all carry the identical Sectigo EV code-signing chain issued to "ORYON TECH LIMITED," and that shared, currently valid certificate is functioning as an active evasion layer rather than a simple trust marker. Static antivirus engines are not fooled: 24 to 44 of roughly 75 to 76 engines flag each file as malicious.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence