GoldenEyeDog Hackers Group Behind DigiCert Breach that Hijacks Code-Signing Certificates
ID: bfee0e58-2bac-5e27-8322-5792a43e8348
STIX ID: report--bfee0e58-2bac-5e27-8322-5792a43e8348
Feed Name: cybersecurityNews.com
Threat Score
GoldenEyeDog (CylindricalCanine) compromised a DigiCert support workstation via a malicious file submitted through the ticketing system, stole certificate activation codes for code-signing tokens, and used Golden Gh0st Loader/RAT (DLL sideloading, encrypted payloads, WebSocket C2) to sign and distribute malicious binaries; the report provides detailed TTPs and numerous IoCs including URLs, file hashes, domains/ports, and hardcoded keys.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
