
EV Certificate Lets ORYON Adware Suite Slip Past Sandbox Scans
Four differently named installers share one ORYON TECH LIMITED Sectigo EV signature and one timestamp, and that valid certificate alone flips sandbox verdicts to 'harmless' even as static engines keep flagging the payload as microleaves/jatif/legion adware-trojans.
Four differently named Windows installers — AdvancedWindowsManager.exe, Windows Updater.exe, Installer_1.0.0.exe and an MSI package called e78a2.msi — carry the exact same code-signing chain: ORYON TECH LIMITED, chaining through Sectigo Public Code Signing CA EV R36 and Sectigo Public Code Signing Root R46, all signed at the identical timestamp of 08:36 AM on 04/23/2026. That precision is the story.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read