hacker-news · Crawled Jul 17, 2026

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

5 IoCs 1 Actors 2 Malware
Read original article ↗

AI Summary

A threat actor cluster known as CylindricalCanine, linked to the broader GoldenEyeDog (APT-Q-27) group, was responsible for a breach at DigiCert in April 2026. The attackers compromised support analysts via a malicious .scr file delivered through a customer support chat, gaining access to initialization codes and stealing code-signing certificates. These certificates were then used to sign malware, including Zhong Stealer and Golden Gh0st RAT, enabling evasion of security detection. The group primarily targets finance organizations in the Asia-Pacific region using phishing and DLL side-loading techniques.

AI-extracted · verify before operational use

Extracted Entities 3 found

Indicators of Compromise 5 extracted

Type Value Detail
Filename update.log Details →
Filename Google Chrome Details →
Filename Microsoft Teams Details →
Filename Google Chrome.exe Details →
Filename Microsoft Teams.exe Details →

MITRE ATT&CK TTPs 34 techniques

T1005 Data from Local System · Collection T1006 Direct Volume Access · Defense Evasion T1012 Query Registry · Discovery T1014 Rootkit · Defense Evasion T1021 Remote Services · Lateral Movement T1021.006 Windows Remote Management · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1036 Masquerading · Defense Evasion T1053.003 Cron · Execution T1053.005 Scheduled Task · Execution T1055 Process Injection · Defense Evasion T1055.012 Process Hollowing · Defense Evasion T1055.015 ListPlanting · Defense Evasion T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1070.003 Clear Command History · Defense Evasion T1070.004 File Deletion · Defense Evasion T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1082 System Information Discovery · Discovery T1085 T1085 T1090 Proxy · Command And Control T1113 Screen Capture · Collection T1133 External Remote Services · Persistence T1190 Exploit Public-Facing Application · Initial Access T1204.002 Malicious File · Execution T1213 Data from Information Repositories · Collection T1213.001 Confluence · Collection T1543.001 Launch Agent · Persistence T1548 Abuse Elevation Control Mechanism · Privilege Escalation T1548.002 Bypass User Account Control · Privilege Escalation T1566 Phishing · Initial Access T1566.001 Spearphishing Attachment · Initial Access