
Single Sectigo EV Certificate Signs Four Malicious Payloads in One Batch
A pay-per-install operation abused a valid Extended Validation code-signing certificate issued to 'ORYON TECH LIMITED' to sign four malicious Windows executables masquerading as a legitimate system utility suite. The campaign delivers GCleaner and EvilCh/CryptOne credential-harvesting implants to victims in Egypt and the United Kingdom through trojanised installers impersonating TopazVideo and ScreenToGif. Layered evasion techniques — including encrypted IE-cache staging, AWS S3 payload hosting, and Cloudflare-proxied C2 domains — place this operation well above the commodity floor of the PPI ecosystem.
Four malicious Windows executables — spanning PE32, PE32+, and MSI formats, collectively masquerading as a legitimate system utility suite called "Advanced Windows Manager" — were signed with a single valid Sectigo Extended Validation code-signing certificate in one batch event on the morning of 23 April 2026. The certificate, issued to an entity named "ORYON TECH LIMITED" under the Sectigo Public Code Signing CA EV R36 chain (serial 21 E3 D5 C7 00 22 7E A0 2E E6 84 AF 4F 8F 88 40, thumbprint…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read