GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
ID: 65018747-6417-5361-a2e8-c1bb5bff1493
STIX ID: report--65018747-6417-5361-a2e8-c1bb5bff1493
Feed Name: CosmicBytez Labs
**Executive Summary:** Expel attributes the April 2026 DigiCert breach to CylindricalCanine, a sub-cluster of the Chinese state-linked APT GoldenEyeDog, which stole code-signing certificates from the Certificate Authority; the report details intrusion tradecraft (targeted phishing/exploited services, lateral movement, certificate exfiltration), explains the severe trust and detection implications for the software ecosystem, and provides defensive recommendations including certificate rotation, auditing CI/CD pipelines, and monitoring revocation status.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
