← Back to Daily Briefing

In April 2026, the threat actor CylindricalCanine, a subgroup of the Chinese-linked GoldenEyeDog (APT-Q-27), compromised DigiCert's code-signing certificate issuance processes. By obtaining legitimate certificates, the attackers signed malicious binaries, specifically the Zhong Stealer, allowing the malware to bypass endpoint detection and response (EDR) systems and OS-level code integrity checks. This breach represents a critical failure in the Certificate Authority (CA) trust model, transitioning the actor's operational focus from targeted gaming fraud to high-impact software supply chain subversion. Remediation requires transitioning to behavior-based detection and auditing anomalous signing patterns.

  • Threat Actor Profile: CylindricalCanine

    • Specialized subgroup of GoldenEyeDog, also tracked as APT-Q-27, Dragon Breath, and Miuuti Group.
    • Historically focused on financial fraud and data theft within the gaming and gambling sectors.
    • Demonstrated a strategic pivot toward infrastructure subversion and large-scale supply chain exploitation.
  • Breach Mechanics: Certificate Subversion

    • Exploited vulnerabilities or bypassed identity verification workflows within DigiCert's issuance pipeline.
    • Successfully acquired legitimate code-signing certificates to masquerade as trusted software vendors.
    • Leveraged high-reputation certificate chains to ensure stealth and persistence on targeted endpoints.
  • Payload Analysis: Zhong Stealer

    • Utilized compromised DigiCert signatures to distribute the Zhong Stealer malware.
    • Valid signatures neutralized standard antivirus (AV) and EDR heuristics that prioritize signed binaries.
    • Technical attribution linked the certificates to the malware through analyzed support chat logs and binary metadata.
  • Technical Impact: Trust Model Erosion

    • Directly compromised the global Certificate Authority (CA) trust hierarchy, undermining digital identity verification.
    • Enabled the bypassing of OS-level code integrity checks that treat signed code as inherently trustworthy.
    • Increased systemic risk for enterprises relying on signed updates for software integrity and authenticity validation.
  • Defensive Strategies & Mitigation

    • Transition from signature-based trust to behavioral analysis (EDR/XDR) for process execution monitoring.
    • Implement strict auditing for unexpected or anomalous certificate issuances associated with organizational identities.
    • Adopt zero-trust architectures and robust supply chain integrity audits for all third-party software execution.

Related posts

  1. gbhackers.com — GoldenEyeDog Threat Group Behind DigiCert Code-Signing Certificate Attack
  2. serisec.com — GoldenEyeDog Hackers Group Behind DigiCert Breach that Hijacks Code-Signing Certificates
  3. feeds.feedburner.com — GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
  4. Gblock
  5. Cybersecuritynews
  6. Hackread
  7. Qualysec
  8. Twit
  9. It-connect
  10. Cbt

LINK COPIED TO CLIPBOARD