GoldenEyeDog / CylindricalCanine Breaches DigiCert Support System to Hijack EV Code-Signing Certificates for Golden Gh0st RAT and Zhong Stealer Distribution — Threadlinqs Intelligence
As of 2026-07-20, GoldenEyeDog / CylindricalCanine Breaches DigiCert Support System to Hijack EV Code-Signing Certificates for Golden Gh0st RAT and Zhong Stealer Distribution is a critical-severity supply chain threat attributed to DragonBreath (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-1579 · Severity: CRITICAL · Status: ACTIVE · Category: SUPPLY_CHAIN
Attribution: DragonBreath · China · FINANCIAL
Chinese cybercrime group GoldenEyeDog (via subgroup CylindricalCanine) compromised DigiCert's customer support ticketing/chat system in April 2026 by delivering a malicious file disguised as a
In April 2026, a threat actor contacted DigiCert's customer support through a chat/ticketing channel and submitted a malicious archive disguised as a customer screenshot. The payload was a Windows .scr screensaver-format executable, a technique the group has used historically to bypass filename-based scrutiny. A DigiCert support employee executed the file, infecting the endpoint on April 2; DigiCert identified the compromise of a first endpoint on April 3 and a second, related endpoint on April 14 -- the delayed detection attributed to malfunctioning endpoint security software. From the compromised support endpoints, the attacker abused a support-analyst capability that allows proxying into customer accounts to access initialization codes tied to code-signing certificate renewal orders. DigiCert's own process treats possession of a valid initialization code plus an approved underlying order as sufficient to retrieve the resulting certificate -- no additional identity verification is required at that step. Using this weakness, the attacker generated legitimate EV Code Signing certificates across multiple customer accounts without the customers' knowledge, effectively laundering malware through a trusted certificate authority.
DigiCert revoked 60 code-signing certificates by April 17, 2026 in response, including 27 explicitly linked to the intruder's activity. Of those 27, 11 were identified after external security researchers submitted certificate problem reports (CPRs) tying the certificates to malware samples signed with them, and 16 were found through DigiCert's internal investigation. Community researchers subsequently confirmed that certificates from this batch had been used to sign samples of the Zhong Stealer malware family, an information-stealer with prior links to Chinese e-crime activity and cryptocurrency theft. DigiCert canceled all pending orders tied to the compromised accounts and implemented remediation including mandatory MFA for administrative support workflows, blocking proxy access to initialization codes for support staff, restricting file types accepted via chat/Salesforce case attachments, and improving support-system logging.
Security researchers at Expel subsequently attributed the operational tradecraft behind the DigiCert intrusion to a cluster they track as CylindricalCanine, assessed as a subgroup of the broader GoldenEyeDog ecosystem -- also referenced in industry reporting under the aliases APT-Q-27, Dragon Breath, and Miuuti Group. GoldenEyeDog is a Chinese cybercrime group historically associated with targeting the online gambling and gaming sectors via trojanized/counterfeit software downloads. The group's toolkit centers on the Golden Gh0st malware family: Golden Gh0st Loader (a DLL-sideloading first-stage loader active since at least 2015), Golden Gh0st RAT (a heavily modified fork of the public Gh0st RAT codebase providing remote command execution, keylogging, screenshot capture, process/service discovery, browser credential theft, proxy tunneling, file deletion, and Windows event-log clearing capability), and Zhong Stealer (a separate information-stealer family used for financially motivated cryptocurrency and credential theft, distributed here using the same stolen-certificate infrastructure).
Post-DigiCert-breach delivery infrastructure observed by researchers includes trojanized files masquerading as images, PDFs, and log files (e.g. newimage.pdf, updat.log, TASLogin.log) staged on Aliyun OSS (Hong Kong region) and, in a June 2026 follow-on wave, Google Cloud Storage buckets. Golden Gh0st RAT's DLL-sideloading component (TASLoginBase.dll / crashreport.dll, loaded by a legitimate-looking host binary such as down.exe or TASLogin) establishes persistence via scheduled tasks and newly created local administrator/backdoor accounts, then beacons to attacker-controlled infrastructure over unencrypted WebSocket connections on non-standard low ports (5188 and 5198) carrying AES-style encrypte
Weaknesses (CWE)
CWE-295, CWE-494, CWE-732
Target sectors: technology, certificate-authority, software-supply-chain, gambling, gaming, finance
Target regions: Global, North America, Asia-Pacific
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
SUPPLY_CHAIN, CRITICAL, threat intelligence, cybersecurity, T1566, T1566.001, T1199, T1195, T1204, T1204.002, T1059.003, T1053.005, T1136.001, T1505