CylindricalCanine cybercrime group linked to April DigiCert certificate theft

 

CylindricalCanine cybercrime group linked to April DigiCert certificate theft

Security researchers have linked the April 2026 DigiCert security incident to a threat group called CylindricalCanine, a subgroup of the Chinese cybercrime organization tracked as GoldenEyeDog. The group is known for targeting gambling, gaming, and finance organizations with malware delivered through fake websites and phishing campaigns.

According to Expel, the attackers gained access to two DigiCert support employees' devices through a malicious file sent via a customer support chat. The threat actors used the access to steal code-signing certificates intended for DigiCert customers and signed their own malware to make it appear legitimate and reduce the chances of detection.

The attackers relied on Golden Gh0st RAT, a modified version of the Gh0st RAT remote access trojan. The malware can steal sensitive data, record keystrokes, take screenshots, run commands, and install additional malware. It is delivered through phishing emails containing links to files disguised as screenshots, which trigger a DLL side-loading attack while displaying a fake HTTP 503 error page to avoid suspicion.

DigiCert said it revoked 60 compromised certificates, including 27 directly linked to the threat actor. The stolen certificates were used to sign Zhong Stealer malware, allowing it to bypass security checks.

Researchers also noted that GoldenEyeDog has used similar Gh0st RAT variants in previous attacks targeting Web3 customer support staff and organizations across the Asia-Pacific region.


Back to the list