Reading the certificate leaves: Understanding GoldenEyeDog’s teams—CylindricalCanine and CuboidalCanine—through code-signing certificates
ID: c18c4aee-0aea-5f94-ae64-b0fcc73ed8e5
STIX ID: report--c18c4aee-0aea-5f94-ae64-b0fcc73ed8e5
Feed Name: Expel Blog
Threat Score
This report analyzes GoldenEyeDog and two distinct subgroups (CylindricalCanine and CuboidalCanine), detailing their use of Golden Gh0st RAT and ValleyRAT, systematic abuse of code-signing certificates (115 certificates, 2,616 signed files), evidence of a DigiCert support-user compromise to intercept certificates, overlap with other criminal actors via certificate resellers, and recommended mitigations (e.g., Windows Defender Application Control and blocklisting TBS hashes).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
