HomeCyber BalkansGoldenEyeDog Threat Group Responsible for DigiCert Code-Signing Certificate Attack

GoldenEyeDog Threat Group Responsible for DigiCert Code-Signing Certificate Attack

Published on

spot_img

GoldenEyeDog Cyber Threat Group: Unraveling a Complex Intrusion into DigiCert

In an evolving landscape of cyber threats, the Chinese cybercrime group known as GoldenEyeDog has captured the attention of cybersecurity experts globally. This group, increasingly characterized as an advanced persistent threat (APT) cluster, has been linked to a notable intrusion into DigiCert, a significant digital certificate authority. This incident facilitated the theft and misuse of legitimate code-signing certificates, marking a critical escalation in the group’s activities.

GoldenEyeDog’s operations date back to at least 2015. However, since 2024, their strategy has involved the consistent exploitation of stolen or compromised code-signing certificates, allowing them to bypass Windows SmartScreen protections. This tactic has enabled them to establish a level of trust for their malicious software, making it increasingly difficult for cybersecurity measures to detect and block their attacks.

The April 2026 incident involving DigiCert stands out not only for its audacity but also for its methodology. The attackers gained access to the device of a DigiCert support employee through malware that was delivered via a seemingly innocuous support ticketing system. This breach allowed the group to intercept certificate initialization codes that were intended for legitimate customers. The stolen codes, which are crucial for activating hardware-backed signing tokens, were later used to sign malware payloads, lending these malicious programs an appearance of legitimacy that complicated their detection by security systems.

Central to GoldenEyeDog’s operations is a sophisticated malware suite now referred to as Golden Gh0st Loader and Golden Gh0st RAT. This malware has previously been misidentified as “Zhong Stealer” in earlier analyses, notably a report by Any.Run in 2025. However, a deeper investigation reveals that these payloads are full-featured remote access trojans (RATs) that draw upon the well-known Gh0st RAT framework.

The Golden Gh0st RAT is highly versatile, housing modular plugins for a range of malicious activities, including credential harvesting, executing remote shell commands, setting up SOCKS proxies, capturing screenshots, and deploying RDP backdoors. Security researchers from Expel attribute this particular wave of attacks to a subgroup of GoldenEyeDog dubbed “CylindricalCanine,” which has also been documented by Qi’anxin.

GoldenEyeDog’s approach to infection remains consistent across various campaigns. Typically, initial access is achieved through phishing emails that masquerade as benign screenshots or support files. These deceptive emails often target enterprise ticketing systems, increasing the chances of successful delivery. Once a victim executes the malicious binary, the malware retrieves further payloads from extensive cloud infrastructures like Alibaba OSS or Google Cloud Storage.

Operational Maturity and Techniques

The sophistication of GoldenEyeDog’s operational infrastructure is notable. Their malware utilizes DLL sideloading, leveraging legitimate executables—such as Tencent-signed binaries—to introduce malicious DLLs that decrypt payloads stored inside .log files. This decrypted payload often launches the Golden Gh0st RAT directly into memory, signifying a streamlined, efficient infection methodology.

Moreover, the decryption process has displayed remarkable consistency across malware samples since 2024, suggesting a stable operational structure within the group. Researchers have even made available decryption tools and samples of the payloads on platforms like GitHub and VirusTotal, facilitating further examination and analysis by the cybersecurity community.

GoldenEyeDog’s RAT communicates over WebSocket protocols, as opposed to traditional TCP, employing custom encrypted frames and hardcoded keys, which adds an additional layer of complexity for detection. Their command-and-control (C2) servers, such as uu.goldeyeuu.io and api.keensie.com, operate on less common ports (5188 and 5198), showcasing their intent to evade conventional network security measures. These servers employ persistent heartbeat mechanisms to maintain connectivity with compromised systems.

The malware suite is endowed with extensive post-exploitation capabilities. It can enumerate running processes, exfiltrate credentials from major web browsers like Chrome and Firefox, and even specific regional applications such as QQ Browser. GoldenEyeDog’s operations also extend to creating persistence through scheduled tasks and BAT scripts, while employing tactics to erase forensic evidence, including Windows Event Logs.

A particular plugin dubbed plugin32.dll enhances the group’s persistence strategies by creating hidden administrative accounts and allowing for automatic RDP logins via registry alterations. Such tactics reflect a well-orchestrated approach to maintaining long-term access to compromised systems.

Evolving Threat Landscape

The abuse of code-signing certificates has become a pressing concern in cybersecurity. Tracking platforms like Cert Graveyard have identified over 75 certificates associated with Golden Gh0st Loader, underscoring a broader trend where financially motivated groups adopt methods historically linked with nation-state actors. This convergence raises alarms among cybersecurity professionals, signaling an urgent need for heightened awareness and robust defenses.

Industry discussions, notably at events like Sleuthcon 2024, emphasize the risks associated with underestimating such threats. With cybercriminals like GoldenEyeDog continuing to refine their tactics, the cybersecurity landscape is likely to face significant challenges ahead. For organizations, recognizing and adapting to these evolving threats is paramount for safeguarding sensitive information and maintaining operational integrity in the digital age.

Source link

Latest articles

Context Bombing Heralds a New Era of Deceptive AI Defense

Emerging AI Security Threats: Insights from Recent Research In an era of rapid technological advancements,...

Technology Implications of AI in Security Webinar

AI’s Transformative Role in Cybersecurity: Insights from Palo Alto Networks AI is reshaping the landscape...

White Hat Hacker Park Chan-am Targets Key Security Challenges in the AI Era

The Ever-Widening Blast Radius of AI Testing In recent years, the rise of local AI...

Survey Reveals Poor Monitoring of Employees’ Shadow AI Use

The Rising Threat of Shadow AI: Organizations Must Reevaluate Their Cybersecurity Strategies In today's digital...

More like this

Context Bombing Heralds a New Era of Deceptive AI Defense

Emerging AI Security Threats: Insights from Recent Research In an era of rapid technological advancements,...

Technology Implications of AI in Security Webinar

AI’s Transformative Role in Cybersecurity: Insights from Palo Alto Networks AI is reshaping the landscape...

White Hat Hacker Park Chan-am Targets Key Security Challenges in the AI Era

The Ever-Widening Blast Radius of AI Testing In recent years, the rise of local AI...