Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Windows Vulnerability Blinds EDR, Bypasses AMSI, AppLocker, Sysmon
July 20, 2026
Paidwork Data Breach Exposes 23 Million Users’ Banking and Personal Data
July 20, 2026
Critical wp2shell RCE Vulnerability Under Active Exploitation
July 20, 2026
Home/CyberSecurity News/GoldenEyeDog Hackers Breach DigiCert, Steal Code-Signing Certificates
CyberSecurity News

GoldenEyeDog Hackers Breach DigiCert, Steal Code-Signing Certificates

Key Takeaways The Chinese cybercrime group GoldenEyeDog, specifically its CylindricalCanine subgroup, breached DigiCert. Attackers exploited a social engineering vector, delivering malware disguised...

Emy Elsamnoudy
Emy Elsamnoudy
July 20, 2026 5 Min Read
5 0

Key Takeaways

  • The Chinese cybercrime group GoldenEyeDog, specifically its CylindricalCanine subgroup, breached DigiCert.
  • Attackers exploited a social engineering vector, delivering malware disguised as customer content via phishing and support tickets.
  • The breach led to the theft of customer certificate activation codes, enabling the signing of malicious files with legitimate-looking certificates.
  • The Golden Gh0st RAT, a versatile remote access trojan, was deployed, providing extensive control and data exfiltration capabilities.
  • The incident highlights the critical risk posed by compromised code-signing certificates, which can bypass standard security measures.

GoldenEyeDog Hackers Breach DigiCert, Steal Code-Signing Certificates

The Chinese cybercrime organization GoldenEyeDog, recognized for its association with the Golden Gh0st malware family, has resurfaced following a significant breach at DigiCert. This incident underscores the severe vulnerabilities inherent in code-signing certificate processes, as attackers leveraged their access to intercept customer certificate activation codes and subsequently sign their own malicious software.

Table Of Content

  • Key Takeaways
  • GoldenEyeDog Hackers Breach DigiCert, Steal Code-Signing Certificates
  • Details of the DigiCert Compromise
  • Loader Tactics and Detection
  • What You Should Do

The infiltration relied on a deceptively simple yet highly effective method to penetrate DigiCert’s secure environment. Malicious files, carefully crafted to appear as legitimate screenshots, were disseminated through phishing emails and customer support ticket submissions. DigiCert personnel, believing they were handling routine customer inquiries, inadvertently opened these files, initiating the compromise.

According to a report by Expel, shared with Cyber Security News (CSN), the specific activity was attributed to a GoldenEyeDog subgroup designated as CylindricalCanine. Researchers have established a clear link between this subgroup and the Golden Gh0st Loader and Golden Gh0st RAT, a suite of malware tools that have been consistently refined and employed across multiple campaigns since 2015.

This breach illuminates a broader challenge for cybersecurity defenders. A valid code-signing certificate bestows an aura of legitimacy upon malicious programs, allowing them to circumvent Windows security protocols and gain a foothold before detection systems or end-users can identify the threat.

Details of the DigiCert Compromise

The breach, which occurred in April 2026, began when a DigiCert support employee executed a malicious file delivered through the company’s internal ticketing system. This initial compromise granted the attackers unauthorized access to initialization codes designated for customers renewing their code-signing certificates.

These codes are essential for activating the hardware tokens used to sign software. By illicitly obtaining them, the GoldenEyeDog group could effectively hijack certificates intended for legitimate customers. This allowed them to sign their malware, making it appear as trusted software and significantly enhancing its ability to bypass conventional security controls. Earlier reports on the weaponized screensaver DigiCert breach had identified the malware involved as Zhong Stealer.

Expel’s in-depth analysis reveals that the malware is far more sophisticated than a simple information stealer. The Golden Gh0st RAT grants its operators extensive remote control capabilities, including the ability to exfiltrate browser credentials, capture screenshots, enumerate running processes, execute arbitrary commands, and meticulously erase forensic traces from compromised systems.

Furthermore, the RAT is designed for persistence, ensuring it remains active even after system reboots. One observed plugin established a backdoor account with administrative privileges and modified system settings to enable remote desktop access, providing attackers with a redundant and stealthy entry point to infected devices.

Loader Tactics and Detection

The Golden Gh0st Loader frequently employs DLL sideloading, a sophisticated technique where a legitimate Windows application is manipulated into loading a malicious dynamic-link library (DLL) placed in the same directory. This malicious DLL then decrypts and loads the actual RAT payload from another file, often disguised as a benign log file. This method makes the infection chain particularly difficult to detect, as trusted applications appear to be part of the execution process.

Similar deceptive tactics have been observed in other recent campaigns, such as the AsyncRAT sideloading incidents, where attackers masked their malicious activities behind seemingly innocuous software components. In the recent GoldenEyeDog campaign, the loader fetched additional components from cloud-hosted services. These included a legitimate executable, necessary runtime files, the malicious DLL, an encrypted payload, and decoy documents. To further reduce suspicion, a fake image or PDF displaying a 503 error was often presented to victims.

The Golden Gh0st RAT communicates with its command-and-control (C2) servers using unencrypted WebSocket connections, though the content transmitted within these connections is encrypted. Analysts have noted the malware’s use of low-numbered ports, specifically 5188 and 5198. This detail can be crucial for defenders when investigating unusual outbound network traffic.

What You Should Do

  • Enhanced Attachment Validation: Implement rigorous validation procedures for all attachments and download links submitted through customer support portals, especially those masquerading as screenshots or customer evidence.
  • Isolated Review Environments: Mandate that staff handling support tickets utilize isolated virtual environments for reviewing unexpected files. Verify the authenticity of suspicious files through a separate, secure communication channel before opening them.
  • Monitor for DLL Sideloading: Deploy monitoring solutions to detect suspicious DLLs being loaded by legitimate applications, as this is a common tactic for Golden Gh0st Loader.
  • Watch for Persistence Mechanisms: Actively monitor for the creation of unexpected scheduled tasks, the addition of new local administrator accounts, and unauthorized modifications to remote desktop settings.
  • Network Traffic Analysis: Implement network detections for outbound WebSocket traffic, particularly to ports 5188 and 5198. Monitor for the distinctive encrypted RAT command traffic associated with Golden Gh0st to identify early signs of compromise.
  • Review Indicators of Compromise (IoCs): Integrate the provided IoCs into your threat intelligence platforms (e.g., MISP, VirusTotal) and SIEM for proactive detection. Remember to de-fang any defanged IP addresses and domains only within controlled environments.
Type Indicator Description
File name 20241224.exe First-stage executable, presented as a photo-themed file
URL hxxps://kkuu.oss-cn-hongkong.aliyuncs.com/ss/uu.txt Configuration file URL used by the 2025 loader
URL hxxps://kkuu.oss-cn-hongkong.aliyuncs.com/ss/down.exe Second-stage executable download
File name down.exe Downloaded executable used in the 2025 infection chain
SHA-256 4eaebd93e23be3427d4c1349d64bef4b5fc455c93aebb9b5b752981e9266488e Hash for down.exe
URL hxxps://kkuu.oss-cn-hongkong.aliyuncs.com/ss/TASLoginBase.dll Malicious DLL download
File name TASLoginBase.dll DLL used for sideloading
SHA-256 1abffe97aafe9916b366da57458a78338598cab9742c2d9e03e4ad0ba11f29bf Hash for TASLoginBase.dll
URL hxxps://kkuu.oss-cn-hongkong.aliyuncs.com/ss/TASLogin.log Encrypted RAT payload download
File name TASLogin.log Encrypted payload loaded by the sideloaded DLL
SHA-256 dd44dabff536a1aa9b845dd891ad483162d4f28913344c93e5d59f648a186098 Hash for TASLogin.log
URL hxxps://storage.googleapis.com/kiki001/as.txt Configuration file URL used in the June 2026 campaign
URL hxxps://storage.googleapis.com/kiki001/updat.exe Legitimate executable used for sideloading
File name updat.exe Legitimate executable used to load the malicious DLL
SHA-256 2b0071007c3f5fa8e949a8de53be03e97901dd505694ca939b575a49e4fdbdbb Hash for updat.exe
URL hxxps://storage.googleapis.com/kiki001/vcruntime140.dll Runtime library download
File name vcruntime140.dll Legitimate Microsoft runtime
SHA-256 8e08575492175e042f093f325b07a5c14ca71e7c581474838db3d48f5aab1312 Hash for vcruntime140.dll
URL hxxps://storage.googleapis.com/kiki001/msvcp140.dll Runtime library download
File name msvcp140.dll Legitimate Microsoft runtime
SHA-256 e4c71980dbb4a1e1a86816687afdaea043b639b531135fc4516fb2429fe623fc Hash for msvcp140.dll
URL hxxps://storage.googleapis.com/kiki001/crashreport.dll Malicious DLL download
File name crashreport.dll Malicious DLL used for sideloading
SHA-256 27b722c66f69e360c4da106daacf3b9eeaabd20634d7e5eff45a28bd70ebfd65 Hash for crashreport.dll
URL hxxps://storage.googleapis.com/kiki001/updat.log Encrypted payload download
File name updat.log Encrypted payload loaded into memory
SHA-256 3313f347e83aaf48ea31fb1d49fc37452f48f81d20a1b93009e2e78385ff4bba Hash for updat.log
URL hxxps://storage.googleapis.com/kiki001/image.jpg Decoy JPEG URL
File name image.jpg Decoy file displaying a 503 error
URL hxxps://storage.googleapis.com/kiki001/newimage.pdf Decoy PDF URL
File name newimage.pdf Decoy PDF containing a 503-error image
SHA-256 f67de637fca127212dc60b9a02f74e66dbd602b3b9f6f6e4f2b75614c1f9e944 Hash for newimage.pdf
SHA-256 81e276aaa3eb9b3f595663c316b3c6414cc3dde5e6cc3a82856b7276acabb7de Golden Gh0st RAT sample observed April 12, 2026
Domain and port uu.goldeyeuu.io:5188 Golden Gh0st RAT command-and-control server
Domain and port wk.goldeyeuu.io:5188 Golden Gh0st RAT command-and-control server
Domain and port api.keensie.com:5198 Golden Gh0st RAT command-and-control server
File name plugin32.dll Persistence plugin that deploys an RDP backdoor
SHA-256 d1b1938963037aa332591a4c999523a05886d1f62d80e03f0adc22630b8671

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachHackerMalwarephishingSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Threat Actors Sell Stolen Starbucks Customer Data on Hacker Forums

Next Post

Critical Microsoft SharePoint RCE Vulnerabilities Under Active Attack

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Microsoft Ends OneDrive Sync App Updates for Windows 10
July 20, 2026
Microsoft Patches Dell USB-C Bug With Out-of-Band Update KB5121767
July 20, 2026
LG Monitors Silently Install Adware on Windows via ScreenX App
July 20, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us