Introducing CylindricalCanine: The GoldenEyeDog subgroup responsible for the April DigiCert incident
ID: fde38e37-17b8-5cf1-883d-4d627d49d3d8
STIX ID: report--fde38e37-17b8-5cf1-883d-4d627d49d3d8
Feed Name: Expel Blog
This report analyzes Golden Gh0st Loader and Golden Gh0st RAT operated by CylindricalCanine (a subgroup of GoldenEyeDog), detailing phishing and DLL sideloading infection chains, modular RAT capabilities (credential theft, keylogging, RDP backdoor, persistence, anti-forensics), custom WebSocket C2 protocol and hardcoded keys, domains/IOCs, and an April 2026 supply-chain impact where attackers accessed a DigiCert support machine to steal code-signing initialization codes and use DigiCert-signed malware to evade SmartScreen.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
