logo

GoldenEyeDog Hackers Group Behind DigiCert Breach that Hijacks Code-Signing Certificates

ID: bfee0e58-2bac-5e27-8322-5792a43e8348

STIX ID: report--bfee0e58-2bac-5e27-8322-5792a43e8348

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

Author: Tushar Subhra Dutta

...
...

GoldenEyeDog (CylindricalCanine) compromised a DigiCert support workstation via a malicious file submitted through the ticketing system, stole certificate activation codes for code-signing tokens, and used Golden Gh0st Loader/RAT (DLL sideloading, encrypted payloads, WebSocket C2) to sign and distribute malicious binaries; the report provides detailed TTPs and numerous IoCs including URLs, file hashes, domains/ports, and hardcoded keys.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.