Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Introducing CylindricalCanine: The GoldenEyeDog subgroup responsible for the April DigiCert incident

2b0071007c3f5fa8e949a8de53be03e97901dd505694ca939b575a49e4fdbdbb

TLP:CLEAR
Active

SHA-256 Hash

Description

Chinese cybercrime group GoldenEyeDog has been active since 2015, regularly updating malware and leveraging code-signing certificates to bypass Windows SmartScreen since 2024. A subgroup called CylindricalCanine uses Golden Gh0st Loader and Golden Gh0st RAT, modified versions of the 2008 Gh0st RAT, primarily targeting finance organizations in the Asia Pacific region through phishing campaigns. In April 2026, these actors compromised a DigiCert support member's device and stole code-signing certificates intended for customers, which they used to sign their own malware. The malware uses DLL sideloading, custom WebSocket protocols for command and control, and includes capabilities for remote access, credential theft, keylogging, SOCKS proxy tunneling, and RDP backdoor creation. Analysis reveals consistent tactics including using legitimate executables to load malicious DLLs that decrypt payloads from files disguised as logs.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Introducing CylindricalCanine: The GoldenEyeDog subgroup responsible for the April DigiCert incident
Pattern Type
STIX
Confidence
75%
Valid From
Jul 17, 2026 02:01
Total Sightings
0
Added
Jul 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 2b0071007c3f5fa8e949a8de53be03e97901dd505694ca939b575a49e4fdbdbb

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.