In April 2026, the threat actor CylindricalCanine, a subgroup of the Chinese-linked GoldenEyeDog (APT-Q-27), compromised DigiCert's code-signing certificate issuance processes. By obtaining legitimate certificates, the attackers signed malicious binaries, specifically the Zhong Stealer, allowing the malware to bypass endpoint detection and response (EDR) systems and OS-level code integrity checks. This breach represents a critical failure in the Certificate Authority (CA) trust model, transitioning the actor's operational focus from targeted gaming fraud to high-impact software supply chain subversion. Remediation requires transitioning to behavior-based detection and auditing anomalous signing patterns.
-
Threat Actor Profile: CylindricalCanine
- Specialized subgroup of GoldenEyeDog, also tracked as APT-Q-27, Dragon Breath, and Miuuti Group.
- Historically focused on financial fraud and data theft within the gaming and gambling sectors.
- Demonstrated a strategic pivot toward infrastructure subversion and large-scale supply chain exploitation.
-
Breach Mechanics: Certificate Subversion
- Exploited vulnerabilities or bypassed identity verification workflows within DigiCert's issuance pipeline.
- Successfully acquired legitimate code-signing certificates to masquerade as trusted software vendors.
- Leveraged high-reputation certificate chains to ensure stealth and persistence on targeted endpoints.
-
Payload Analysis: Zhong Stealer
- Utilized compromised DigiCert signatures to distribute the Zhong Stealer malware.
- Valid signatures neutralized standard antivirus (AV) and EDR heuristics that prioritize signed binaries.
- Technical attribution linked the certificates to the malware through analyzed support chat logs and binary metadata.
-
Technical Impact: Trust Model Erosion
- Directly compromised the global Certificate Authority (CA) trust hierarchy, undermining digital identity verification.
- Enabled the bypassing of OS-level code integrity checks that treat signed code as inherently trustworthy.
- Increased systemic risk for enterprises relying on signed updates for software integrity and authenticity validation.
-
Defensive Strategies & Mitigation
- Transition from signature-based trust to behavioral analysis (EDR/XDR) for process execution monitoring.
- Implement strict auditing for unexpected or anomalous certificate issuances associated with organizational identities.
- Adopt zero-trust architectures and robust supply chain integrity audits for all third-party software execution.
Related posts
- gbhackers.com — GoldenEyeDog Threat Group Behind DigiCert Code-Signing Certificate Attack
- serisec.com — GoldenEyeDog Hackers Group Behind DigiCert Breach that Hijacks Code-Signing Certificates
- feeds.feedburner.com — GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
- Gblock
- Cybersecuritynews
- Hackread
- Qualysec
- Twit
- It-connect
- Cbt