GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
ID: 65111248-d364-5214-8186-9f9865e3fcb4
STIX ID: report--65111248-d364-5214-8186-9f9865e3fcb4
Feed Name: The Hacker News
Researchers attribute an April 2026 compromise of DigiCert to CylindricalCanine, a subgroup of GoldenEyeDog, which used customer-chat phishing and multi-stage loaders (including RONINGLOADER/Golden Gh0st Loader and NSIS installers) to deploy a modified Gh0st RAT (Golden Gh0st RAT) and steal EV code-signing certificates (60 revoked, 27 linked) that were then used to sign Zhong Stealer artifacts; the report covers the attack chain (DLL side-loading, decoy PDFs, encrypted payloads), the abused support-portal initialization codes, impacted CAs, and the malware’s extensive data-stealing and persistence capabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
