Unveiling the GoldenEyeDog Subgroup: DigiCert Breach and Code-Signing Certificate Theft (2026)

The recent DigiCert breach, attributed to the threat activity cluster CylindricalCanine, has shed light on the evolving tactics of Chinese cybercrime groups. This incident highlights the group's ability to exploit code-signing certificates and the potential implications for the security of digital signatures. The breach occurred when GoldenEyeDog, a subgroup of CylindricalCanine, accessed a support member's device at DigiCert, a code-signing certificate provider, and stole certificates intended for DigiCert customers. This attack showcased the malware's capabilities and the operators' technical prowess.

The core of CylindricalCanine's operations revolves around a modified version of Gh0st RAT, known as Golden Gh0st RAT. This modular malware is delivered through a multi-stage loader called RONINGLOADER, which disguises itself as legitimate programs like Google Chrome and Microsoft Teams. The group has been observed targeting customer support staff of Web3 companies, using suspicious links sent via chat to deliver the Gh0st RAT. This campaign is consistent with the group's broader targeting of finance organizations in the Asia-Pacific region.

Golden Gh0st RAT shares behavioral and tactical overlaps with malware detected by QiAnXin in 2020, which was aimed at the gambling industry since 2019. It also overlaps with Zhong Stealer, a malware campaign documented by ANY.RUN in February 2025. The DigiCert compromise involved the abuse of code-signing certificates, where CylindricalCanine gained unauthorized access to DigiCert and intercepted certificates intended for DigiCert customers. These certificates were then used to sign their own malware, avoiding detection.

The attack chain employed by CylindricalCanine involves phishing emails with files disguised as screenshots. When clicked, these files download additional payloads from an external server, triggering a DLL side-loading chain. The final stage is Golden Gh0st RAT, which has a wide range of capabilities, including setting up persistence, stealing sensitive data, and executing various malicious actions. The group targets applications like Skype, Google Chrome, and Mozilla Firefox for data collection.

This incident adds to a growing list of threat actors, such as Black Basta, TamperedChef (EvilAI), and Rhysida, known for their abuse of code-signing certificates. The use of Golden Gh0st RAT in phishing emails and support portal submissions highlights the group's adaptability and the challenges in detecting and mitigating such attacks. The implications of this breach extend beyond DigiCert, underscoring the need for enhanced security measures and vigilance in the face of evolving cyber threats.

Unveiling the GoldenEyeDog Subgroup: DigiCert Breach and Code-Signing Certificate Theft (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Wyatt Volkman LLD

Last Updated:

Views: 6487

Rating: 4.6 / 5 (46 voted)

Reviews: 85% of readers found this page helpful

Author information

Name: Wyatt Volkman LLD

Birthday: 1992-02-16

Address: Suite 851 78549 Lubowitz Well, Wardside, TX 98080-8615

Phone: +67618977178100

Job: Manufacturing Director

Hobby: Running, Mountaineering, Inline skating, Writing, Baton twirling, Computer programming, Stone skipping

Introduction: My name is Wyatt Volkman LLD, I am a handsome, rich, comfortable, lively, zealous, graceful, gifted person who loves writing and wants to share my knowledge and understanding with you.