logo

GoldenEyeDog Threat Group Behind DigiCert Code-Signing Certificate Attack

ID: 7a1c5a04-6dd8-510b-b1b2-edd5f7012b6f

STIX ID: report--7a1c5a04-6dd8-510b-b1b2-edd5f7012b6f

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

Author: Mayura Kathir

...
...

**Executive summary:** GoldenEyeDog (aka APT-Q-27) conducted a sophisticated intrusion into DigiCert in April 2026 to intercept certificate initialization codes and abuse legitimate code-signing certificates to sign Golden Gh0st Loader/RAT payloads, enabling evasion of Windows SmartScreen and trusted distribution; the campaign leverages DLL sideloading, WebSocket-based C2, modular RAT plugins for credential theft, persistence and RDP backdoors, and persistent infrastructure (e.g., uu.goldeyeuu.io:5188, api.keensie.com:5198).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.