GoldenEyeDog Threat Group Behind DigiCert Code-Signing Certificate Attack
ID: 7a1c5a04-6dd8-510b-b1b2-edd5f7012b6f
STIX ID: report--7a1c5a04-6dd8-510b-b1b2-edd5f7012b6f
Feed Name: GBHackers
**Executive summary:** GoldenEyeDog (aka APT-Q-27) conducted a sophisticated intrusion into DigiCert in April 2026 to intercept certificate initialization codes and abuse legitimate code-signing certificates to sign Golden Gh0st Loader/RAT payloads, enabling evasion of Windows SmartScreen and trusted distribution; the campaign leverages DLL sideloading, WebSocket-based C2, modular RAT plugins for credential theft, persistence and RDP backdoors, and persistent infrastructure (e.g., uu.goldeyeuu.io:5188, api.keensie.com:5198).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
