logo

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

ID: 65111248-d364-5214-8186-9f9865e3fcb4

STIX ID: report--65111248-d364-5214-8186-9f9865e3fcb4

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-07-17

Date Updated: 2026-07-17

Author: [email protected] (The Hacker News)

...
...

Researchers attribute an April 2026 compromise of DigiCert to CylindricalCanine, a subgroup of GoldenEyeDog, which used customer-chat phishing and multi-stage loaders (including RONINGLOADER/Golden Gh0st Loader and NSIS installers) to deploy a modified Gh0st RAT (Golden Gh0st RAT) and steal EV code-signing certificates (60 revoked, 27 linked) that were then used to sign Zhong Stealer artifacts; the report covers the attack chain (DLL side-loading, decoy PDFs, encrypted payloads), the abused support-portal initialization codes, impacted CAs, and the malware’s extensive data-stealing and persistence capabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.