← Back to Daily Briefing

In April 2026, the threat actor CylindricalCanine, a subgroup of the Chinese-linked GoldenEyeDog (APT-Q-27), compromised DigiCert's code-signing certificate issuance processes. By obtaining legitimate certificates, the attackers signed malicious binaries, specifically the Zhong Stealer, allowing the malware to bypass endpoint detection and response (EDR) systems and OS-level code integrity checks. This breach represents a critical failure in the Certificate Authority (CA) trust model, transitioning the actor's operational focus from targeted gaming fraud to high-impact software supply chain subversion. Remediation requires transitioning to behavior-based detection and auditing anomalous signing patterns.

  • Threat Actor Profile: CylindricalCanine

    • Specialized subgroup of GoldenEyeDog, also tracked as APT-Q-27, Dragon Breath, and Miuuti Group.
    • Historically focused on financial fraud and data theft within the gaming and gambling sectors.
    • Demonstrated a strategic pivot toward infrastructure subversion and large-scale supply chain exploitation.
  • Breach Mechanics: Certificate Subversion

    • Exploited vulnerabilities or bypassed identity verification workflows within DigiCert's issuance pipeline.
    • Successfully acquired legitimate code-signing certificates to masquerade as trusted software vendors.
    • Leveraged high-reputation certificate chains to ensure stealth and persistence on targeted endpoints.
  • Payload Analysis: Zhong Stealer

    • Utilized compromised DigiCert signatures to distribute the Zhong Stealer malware.
    • Valid signatures neutralized standard antivirus (AV) and EDR heuristics that prioritize signed binaries.
    • Technical attribution linked the certificates to the malware through analyzed support chat logs and binary metadata.
  • Technical Impact: Trust Model Erosion

    • Directly compromised the global Certificate Authority (CA) trust hierarchy, undermining digital identity verification.
    • Enabled the bypassing of OS-level code integrity checks that treat signed code as inherently trustworthy.
    • Increased systemic risk for enterprises relying on signed updates for software integrity and authenticity validation.
  • Defensive Strategies & Mitigation

    • Transition from signature-based trust to behavioral analysis (EDR/XDR) for process execution monitoring.
    • Implement strict auditing for unexpected or anomalous certificate issuances associated with organizational identities.
    • Adopt zero-trust architectures and robust supply chain integrity audits for all third-party software execution.

Related posts

  1. gbhackers.com — GoldenEyeDog Threat Group Behind DigiCert Code-Signing Certificate Attack
  2. serisec.com — GoldenEyeDog Hackers Group Behind DigiCert Breach that Hijacks Code-Signing Certificates
  3. techjacksolutions.com — CylindricalCanine Subgroup of GoldenEyeDog Breaches DigiCert Support Portal, Weaponizes Stolen EV Code-Signing Certificates to Sign Zhong Stealer Malware
  4. blackhatnews.tokyo — Golden Gh0st RAT:DigiCert証明書窃取事件の内幕
  5. feeds.feedburner.com — GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
  6. Gblock
  7. Cybersecuritynews
  8. Hackread
  9. Qualysec
  10. Twit
  11. It-connect
  12. Cbt
  13. Cyberpress
  14. Ministang
  15. Ctoatncsc
  16. Securitybrief
  17. Mallory
  18. Malwaretips
  19. Medium
  20. Attack

LINK COPIED TO CLIPBOARD