GoldenEyeDog Hackers Breach DigiCert, Steal Code-Signing Certificates
Key Takeaways The Chinese cybercrime group GoldenEyeDog, specifically its CylindricalCanine subgroup, breached DigiCert. Attackers exploited a social engineering vector, delivering malware disguised...
Key Takeaways
- The Chinese cybercrime group GoldenEyeDog, specifically its CylindricalCanine subgroup, breached DigiCert.
- Attackers exploited a social engineering vector, delivering malware disguised as customer content via phishing and support tickets.
- The breach led to the theft of customer certificate activation codes, enabling the signing of malicious files with legitimate-looking certificates.
- The Golden Gh0st RAT, a versatile remote access trojan, was deployed, providing extensive control and data exfiltration capabilities.
- The incident highlights the critical risk posed by compromised code-signing certificates, which can bypass standard security measures.
GoldenEyeDog Hackers Breach DigiCert, Steal Code-Signing Certificates
The Chinese cybercrime organization GoldenEyeDog, recognized for its association with the Golden Gh0st malware family, has resurfaced following a significant breach at DigiCert. This incident underscores the severe vulnerabilities inherent in code-signing certificate processes, as attackers leveraged their access to intercept customer certificate activation codes and subsequently sign their own malicious software.
Table Of Content
The infiltration relied on a deceptively simple yet highly effective method to penetrate DigiCert’s secure environment. Malicious files, carefully crafted to appear as legitimate screenshots, were disseminated through phishing emails and customer support ticket submissions. DigiCert personnel, believing they were handling routine customer inquiries, inadvertently opened these files, initiating the compromise.
According to a report by Expel, shared with Cyber Security News (CSN), the specific activity was attributed to a GoldenEyeDog subgroup designated as CylindricalCanine. Researchers have established a clear link between this subgroup and the Golden Gh0st Loader and Golden Gh0st RAT, a suite of malware tools that have been consistently refined and employed across multiple campaigns since 2015.
This breach illuminates a broader challenge for cybersecurity defenders. A valid code-signing certificate bestows an aura of legitimacy upon malicious programs, allowing them to circumvent Windows security protocols and gain a foothold before detection systems or end-users can identify the threat.
Details of the DigiCert Compromise
The breach, which occurred in April 2026, began when a DigiCert support employee executed a malicious file delivered through the company’s internal ticketing system. This initial compromise granted the attackers unauthorized access to initialization codes designated for customers renewing their code-signing certificates.
These codes are essential for activating the hardware tokens used to sign software. By illicitly obtaining them, the GoldenEyeDog group could effectively hijack certificates intended for legitimate customers. This allowed them to sign their malware, making it appear as trusted software and significantly enhancing its ability to bypass conventional security controls. Earlier reports on the weaponized screensaver DigiCert breach had identified the malware involved as Zhong Stealer.
Expel’s in-depth analysis reveals that the malware is far more sophisticated than a simple information stealer. The Golden Gh0st RAT grants its operators extensive remote control capabilities, including the ability to exfiltrate browser credentials, capture screenshots, enumerate running processes, execute arbitrary commands, and meticulously erase forensic traces from compromised systems.
Furthermore, the RAT is designed for persistence, ensuring it remains active even after system reboots. One observed plugin established a backdoor account with administrative privileges and modified system settings to enable remote desktop access, providing attackers with a redundant and stealthy entry point to infected devices.
Loader Tactics and Detection
The Golden Gh0st Loader frequently employs DLL sideloading, a sophisticated technique where a legitimate Windows application is manipulated into loading a malicious dynamic-link library (DLL) placed in the same directory. This malicious DLL then decrypts and loads the actual RAT payload from another file, often disguised as a benign log file. This method makes the infection chain particularly difficult to detect, as trusted applications appear to be part of the execution process.
Similar deceptive tactics have been observed in other recent campaigns, such as the AsyncRAT sideloading incidents, where attackers masked their malicious activities behind seemingly innocuous software components. In the recent GoldenEyeDog campaign, the loader fetched additional components from cloud-hosted services. These included a legitimate executable, necessary runtime files, the malicious DLL, an encrypted payload, and decoy documents. To further reduce suspicion, a fake image or PDF displaying a 503 error was often presented to victims.
The Golden Gh0st RAT communicates with its command-and-control (C2) servers using unencrypted WebSocket connections, though the content transmitted within these connections is encrypted. Analysts have noted the malware’s use of low-numbered ports, specifically 5188 and 5198. This detail can be crucial for defenders when investigating unusual outbound network traffic.
What You Should Do
- Enhanced Attachment Validation: Implement rigorous validation procedures for all attachments and download links submitted through customer support portals, especially those masquerading as screenshots or customer evidence.
- Isolated Review Environments: Mandate that staff handling support tickets utilize isolated virtual environments for reviewing unexpected files. Verify the authenticity of suspicious files through a separate, secure communication channel before opening them.
- Monitor for DLL Sideloading: Deploy monitoring solutions to detect suspicious DLLs being loaded by legitimate applications, as this is a common tactic for Golden Gh0st Loader.
- Watch for Persistence Mechanisms: Actively monitor for the creation of unexpected scheduled tasks, the addition of new local administrator accounts, and unauthorized modifications to remote desktop settings.
- Network Traffic Analysis: Implement network detections for outbound WebSocket traffic, particularly to ports 5188 and 5198. Monitor for the distinctive encrypted RAT command traffic associated with Golden Gh0st to identify early signs of compromise.
- Review Indicators of Compromise (IoCs): Integrate the provided IoCs into your threat intelligence platforms (e.g., MISP, VirusTotal) and SIEM for proactive detection. Remember to de-fang any defanged IP addresses and domains only within controlled environments.
| Type | Indicator | Description |
|---|---|---|
| File name | 20241224.exe |
First-stage executable, presented as a photo-themed file |
| URL | hxxps://kkuu.oss-cn-hongkong.aliyuncs.com/ss/uu.txt |
Configuration file URL used by the 2025 loader |
| URL | hxxps://kkuu.oss-cn-hongkong.aliyuncs.com/ss/down.exe |
Second-stage executable download |
| File name | down.exe |
Downloaded executable used in the 2025 infection chain |
| SHA-256 | 4eaebd93e23be3427d4c1349d64bef4b5fc455c93aebb9b5b752981e9266488e |
Hash for down.exe |
| URL | hxxps://kkuu.oss-cn-hongkong.aliyuncs.com/ss/TASLoginBase.dll |
Malicious DLL download |
| File name | TASLoginBase.dll |
DLL used for sideloading |
| SHA-256 | 1abffe97aafe9916b366da57458a78338598cab9742c2d9e03e4ad0ba11f29bf |
Hash for TASLoginBase.dll |
| URL | hxxps://kkuu.oss-cn-hongkong.aliyuncs.com/ss/TASLogin.log |
Encrypted RAT payload download |
| File name | TASLogin.log |
Encrypted payload loaded by the sideloaded DLL |
| SHA-256 | dd44dabff536a1aa9b845dd891ad483162d4f28913344c93e5d59f648a186098 |
Hash for TASLogin.log |
| URL | hxxps://storage.googleapis.com/kiki001/as.txt |
Configuration file URL used in the June 2026 campaign |
| URL | hxxps://storage.googleapis.com/kiki001/updat.exe |
Legitimate executable used for sideloading |
| File name | updat.exe |
Legitimate executable used to load the malicious DLL |
| SHA-256 | 2b0071007c3f5fa8e949a8de53be03e97901dd505694ca939b575a49e4fdbdbb |
Hash for updat.exe |
| URL | hxxps://storage.googleapis.com/kiki001/vcruntime140.dll |
Runtime library download |
| File name | vcruntime140.dll |
Legitimate Microsoft runtime |
| SHA-256 | 8e08575492175e042f093f325b07a5c14ca71e7c581474838db3d48f5aab1312 |
Hash for vcruntime140.dll |
| URL | hxxps://storage.googleapis.com/kiki001/msvcp140.dll |
Runtime library download |
| File name | msvcp140.dll |
Legitimate Microsoft runtime |
| SHA-256 | e4c71980dbb4a1e1a86816687afdaea043b639b531135fc4516fb2429fe623fc |
Hash for msvcp140.dll |
| URL | hxxps://storage.googleapis.com/kiki001/crashreport.dll |
Malicious DLL download |
| File name | crashreport.dll |
Malicious DLL used for sideloading |
| SHA-256 | 27b722c66f69e360c4da106daacf3b9eeaabd20634d7e5eff45a28bd70ebfd65 |
Hash for crashreport.dll |
| URL | hxxps://storage.googleapis.com/kiki001/updat.log |
Encrypted payload download |
| File name | updat.log |
Encrypted payload loaded into memory |
| SHA-256 | 3313f347e83aaf48ea31fb1d49fc37452f48f81d20a1b93009e2e78385ff4bba |
Hash for updat.log |
| URL | hxxps://storage.googleapis.com/kiki001/image.jpg |
Decoy JPEG URL |
| File name | image.jpg |
Decoy file displaying a 503 error |
| URL | hxxps://storage.googleapis.com/kiki001/newimage.pdf |
Decoy PDF URL |
| File name | newimage.pdf |
Decoy PDF containing a 503-error image |
| SHA-256 | f67de637fca127212dc60b9a02f74e66dbd602b3b9f6f6e4f2b75614c1f9e944 |
Hash for newimage.pdf |
| SHA-256 | 81e276aaa3eb9b3f595663c316b3c6414cc3dde5e6cc3a82856b7276acabb7de |
Golden Gh0st RAT sample observed April 12, 2026 |
| Domain and port | uu.goldeyeuu.io:5188 |
Golden Gh0st RAT command-and-control server |
| Domain and port | wk.goldeyeuu.io:5188 |
Golden Gh0st RAT command-and-control server |
| Domain and port | api.keensie.com:5198 |
Golden Gh0st RAT command-and-control server |
| File name | plugin32.dll |
Persistence plugin that deploys an RDP backdoor |
| SHA-256 | d1b1938963037aa332591a4c999523a05886d1f62d80e03f0adc22630b8671
|



No Comment! Be the first one.