The record
Written from the 1 report below. Nothing here is unsourced.
- Cybersecurity firm Expel has attributed the April 2026 breach of certificate authority DigiCert to a group called CylindricalCanine, a subgroup of the Chinese cybercrime cluster GoldenEyeDog.
- The attackers posed as a customer in a support chat, sent a malicious file disguised as a screenshot, and used access to a support analyst's workstation to steal initialization codes for EV code-signing certificates.
- DigiCert revoked 60 certificates, 27 of which were linked to the threat actor, and the stolen certificates were used to sign malware to help it evade detection.
- The incident matters because code-signing certificates let malware appear trustworthy, and DigiCert has since changed its portal to hide initialization codes from support accounts.
What to watch next
- Whether DigiCert customers affected by the 60 revoked certificates face further malware signed with stolen certificates.
- New campaigns from GoldenEyeDog subgroups, including continued use of RONINGLOADER and Golden Gh0st RAT.
- Further targeting of finance organizations in the Asia-Pacific region and Web3 company support staff.
Coverage1
1 report
English national1
All filed from India
Named China · United States
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
