C&CMembers
C&C

EV Certificate Lets ORYON Adware Suite Slip Past Sandbox Scans

Four differently named installers share one ORYON TECH LIMITED Sectigo EV signature and one timestamp, and that valid certificate alone flips sandbox verdicts to 'harmless' even as static engines keep flagging the payload as microleaves/jatif/legion adware-trojans.

Aug 1, 2026, 05:38 (UTC+9)Last seenAug 1, 2026Severity100ByCTX TeamIOC41MITRE22RegionsBECADZGBIE

Four differently named Windows installers — AdvancedWindowsManager.exe, Windows Updater.exe, Installer_1.0.0.exe and an MSI package called e78a2.msi — carry the exact same code-signing chain: ORYON TECH LIMITED, chaining through Sectigo Public Code Signing CA EV R36 and Sectigo Public Code Signing Root R46, all signed at the identical timestamp of 08:36 AM on 04/23/2026. That precision is the story.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence