INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
DigiCert Breach Linked to GoldenEyeDog Subgroup Code-Signing Certificate Theft
| 2026-07-17 16:39 DATA BREACH
Executive Summary
AI-generated
In April 2026, a Chinese cybercrime group known as GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group) linked to the DigiCert security incident used malware to access a support member's device at DigiCert, a code-signing certificate provider. The attackers targeted finance organizations in the Asia-Pacific region using malware consistent with other Chinese cybercrime activity. Golden Gh0st RAT, a modified version of Farfli, was delivered via Golden Gh0st Loader and shared behavioral and tactical overlaps with previously detected malware such as Zhong Stealer and QiAnXin's 2020 payload. The attackers abused code-signing certificates to gain unauthorized access to DigiCert customers' intended certificates and sign their own malware to avoid detection.
Technical Mitigations AI-generated
• Patch the Golden Gh0st RAT vulnerability in NSIS installers to prevent exploitation by CylindricalCanine.
• Block or hunt for suspicious links sent via customer support chat channels, as observed in a multi-stage attack directed at Web3 companies earlier this year.
• Monitor code-signing certificate abuse and revoke certificates issued by compromised internal support portals, such as the 60 certificates revoked by DigiCert after gaining unauthorized access to their internal support portal.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
up•••••.log
an•••••.run
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Incident Timeline
Tactical Metrics
Intelligence Sources
The Hacker News
2026-07-17