logo

Introducing CylindricalCanine: The GoldenEyeDog subgroup responsible for the April DigiCert incident

ID: fde38e37-17b8-5cf1-883d-4d627d49d3d8

STIX ID: report--fde38e37-17b8-5cf1-883d-4d627d49d3d8

Feed Name: Expel Blog

Threat Score
85/100

Date Published: 2026-07-15

Date Updated: 2026-07-16

...
...

This report analyzes Golden Gh0st Loader and Golden Gh0st RAT operated by CylindricalCanine (a subgroup of GoldenEyeDog), detailing phishing and DLL sideloading infection chains, modular RAT capabilities (credential theft, keylogging, RDP backdoor, persistence, anti-forensics), custom WebSocket C2 protocol and hardcoded keys, domains/IOCs, and an April 2026 supply-chain impact where attackers accessed a DigiCert support machine to steal code-signing initialization codes and use DigiCert-signed malware to evade SmartScreen.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.