Published on July 19, 2026

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft


Severity
Medium

Detail

Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster tracked as CylindricalCanine. According to Expel, CylindricalCanine is a subgroup of GoldenEyeDog (also known as APT-Q-27, Dragon Breath, and Miuuti Group), a Chinese cybercrime group active since at least 2015 and known for targeting the gambling and gaming sectors by distributing malware through counterfeit websites.

Expel reported that GoldenEyeDog used its malware to compromise a DigiCert support employee’s device and leveraged the access to steal code-signing certificates intended for DigiCert customers. Researchers stated that the incident demonstrated both the malware’s capabilities and the operators’ ability to abuse trusted certificate infrastructure.

The group’s operations are centered on Golden Gh0st RAT, a modified version of Gh0st RAT delivered through Golden Gh0st Loader. Expel also noted that another threat cluster within GoldenEyeDog is likely responsible for using RONINGLOADER, a multi-stage loader previously documented by Elastic Security Labs.

How?

Expel stated that CylindricalCanine primarily distributes phishing emails containing links that download files disguised as screenshots from external servers. The downloaded files initiate a DLL side-loading attack chain by using a legitimate executable to load a malicious DLL while displaying a decoy PDF containing an HTTP 503 “Service Unavailable” error. The malicious DLL then loads an encrypted payload named update.log, which ultimately deploys Golden Gh0st RAT.

Golden Gh0st RAT can establish persistence, stealing sensitive data, creating SOCKS proxy tunnels, suppressing display output, logging keystrokes, capturing screenshots, enumerating processes, executing shell commands, dropping additional payloads, and clearing Windows Event Logs. The malware also targets applications including Skype, Google Chrome, Mozilla Firefox, 360 Secure Browser, 360 Speed Browser, and Tencent QQ Browser for data collection.

During the DigiCert compromise, the attackers contacted DigiCert support through a customer chat channel and delivered a ZIP archive disguised as a customer screenshot. The archive contained a malicious .scr executable that compromised two DigiCert support analyst workstations.

The attackers then abused a customer support portal feature that allowed authenticated support analysts to access customer accounts from the customer’s perspective. Using this functionality, they obtained initialization codes for approved but pending EV Code Signing certificate orders. DigiCert stated that possession of an initialization code together with an approved order was sufficient to obtain EV Code Signing certificates.

Figure 1: Golden GH0st RAT Infection Chain

Impact

The compromise enabled the attackers to fraudulently obtain code-signing certificates intended for DigiCert customers and use them to digitally sign their own malware to evade detection. Following the incident, DigiCert revoked 60 code-signing certificates issued by:

  • DigiCert Trusted G4 Code Signing RSA4096 SHA256 2021 CA1
  • DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
  • GoGetSSL G4 CS RSA4096 SHA256 2022 CA-1
  • Verokey High Assurance Secure Code EV

Of the revoked certificates, 27 were explicitly linked to the threat actor and were used to sign Zhong Stealer malware artifacts. Expel also stated that Golden Gh0st RAT shares behavioral and tactical similarities with malware previously associated with attacks targeting the gambling industry and overlaps with malware documented by ANY.RUN as Zhong Stealer.

Recommendations

DigiCert stated that it has implemented code changes to mask initialization codes from proxied users on both its U.S. and E.U. platforms through both the user interface (UI) and API, preventing proxied users from viewing initialization codes.

Conclusion

The findings attribute the DigiCert compromise to the CylindricalCanine subgroup of GoldenEyeDog and show how the threat actor combined phishing, DLL side-loading, and Golden Gh0st RAT to compromise DigiCert support systems and obtain code-signing certificates. The incident also highlights the threat actor’s continued use of trusted certificates to digitally sign malware and evade detection.

Source
https://thehackernews.com/2026/07/goldeneyedog-subgroup-linked-to.html