Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors cylindricalcanine

Also known as: header, tracked as, Broomstick, GoldenEyeDog, ProfSvc, Popa, services, other system resources, public key cryptography, one private, the file association, metamorphic, magic bytes, handler, Netshell, the IconEnvironmentDataBlock, mutating code

Description

Chinese cybercrime group GoldenEyeDog has been active since 2015, regularly updating malware and leveraging code-signing certificates to bypass Windows SmartScreen since 2024. A subgroup called CylindricalCanine uses Golden Gh0st Loader and Golden Gh0st RAT, modified versions of the 2008 Gh0st RAT, primarily targeting finance organizations in the Asia Pacific region through phishing campaigns. In April 2026, these actors compromised a DigiCert support member's device and stole code-signing certificates intended for customers, which they used to sign their own malware. The malware uses DLL sideloading, custom WebSocket protocols for command and control, and includes capabilities for remote access, credential theft, keylogging, SOCKS proxy tunneling, and RDP backdoor creation. Analysis reveals consistent tactics including using legitimate executables to load malicious DLLs that decrypt payloads from files disguised as logs.

Goals & Targeting

Targeted Sectors

Financial services
Media
Government
Defense
Telecommunications
Information technology
Energy
Manufacturing

Targeted Countries / Regions

CN
US
RO
AU
JP
TW

AI Analysis

· 1 week ago

Executive Summary

CylindricalCanine, a subgroup of the Chinese cybercrime group GoldenEyeDog, is a sophisticated threat actor targeting financial organizations in the Asia Pacific region. Known for leveraging modified versions of the 2008 Gh0st RAT, such as Golden Gh0st Loader and RAT, this group has been active since 2015. In April 2026, they stole code-signing certificates from a DigiCert support member, enabling them to bypass Windows SmartScreen. Their malware includes capabilities for remote access, credential theft, keylogging, SOCKS proxy tunneling, and RDP backdoor creation.

Goals & Targeting

CylindricalCanine likely seeks financial gain, focusing on sectors with high economic value such as finance. Their targeting of financial organizations in the Asia Pacific region suggests a strategic focus on regions with significant financial activity and potentially weaker defenses. The group's use of stolen code-signing certificates indicates an aim to enhance their operational persistence and evade detection.

Enhanced Description

CylindricalCanine operates as part of the larger GoldenEyeDog cybercrime group and has targeted financial services globally. The subgroup primarily focuses on Asia Pacific regions, conducting phishing campaigns to distribute their malware. Since 2015, they have continuously updated their tools, including leveraging legitimate executables to load malicious DLLs, which decrypt payloads from files disguised as logs. In a notable incident in April 2026, the group compromised a DigiCert support member's device, stealing code-signing certificates. These certificates were used to sign their malware, further enhancing its evasion capabilities. The malware employs custom WebSocket protocols for command and control (C2), making it harder to detect. CylindricalCanine's activities highlight the growing sophistication of cybercriminal groups targeting financial institutions for potential monetary gains.

Key Capabilities

  • DLL sideloading
  • Custom WebSocket protocols for C2
  • Remote access capabilities
  • Credential theft
  • Keylogging
  • SOCKS proxy tunneling
  • RDP backdoor creation

MITRE ATT&CK Tactics

Lateral Movement
Exfiltration
Initial Access
Credential Access
Discovery

ATT&CK Techniques

T1059.003
T1566.001
T1078
T1547
T1003
T1207

Software / Tooling

Golden Gh0st Loader
Golden Gh0st RAT
Modified Gh0st RAT

Campaigns & Victims

CylindricalCanine's campaign patterns include phishing-based distribution of malware, leveraging stolen code-signing certificates for persistence. Their operational tempo suggests a focus on high-value targets in finance, particularly in the Asia Pacific region. Notable past operations include the April 2026 compromise of a DigiCert support member, highlighting their ability to exploit supply chain vulnerabilities.

IOC Patterns

  • Spear-phishing campaigns targeting financial services
  • Distribution of malware signed with stolen code-signing certificates
  • Custom WebSocket traffic for C2 communications
  • DLL sideloading from legitimate executables

Recommended Actions

  • Implement rigorous supply chain security measures to prevent compromise of vendor accounts.
  • Monitor for unusual WebSocket traffic in network communications.
  • Enhance endpoint detection and response (EDR) to detect malicious DLL sideloading and custom protocols.
  • Regularly audit code-signing certificates and implement multi-factor authentication for certificate management.

Suggested Tags

APT
cybercrime
financial-sector
malware
espionage

Confidence Assessment

High confidence in the data due to clear descriptions of operations, TTPs, and tools. No gaps identified as the information provided is comprehensive.

ATT&CK Techniques

Exfiltration
1 technique
Initial Access
1 technique
Privilege Escalation
1 technique
Reconnaissance
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: services
  2. attack.mitre.org — Cited by web research for: PowerShell
  3. redcanary.com — Cited by web research for: SocGholish
  4. research.checkpoint.com — Cited by web research for: PsExec

Intel Summary

40

Techniques

45

Tools

0

Campaigns

42

IOCs

0

Observed Data

13

Tactics

Tags

Critical Infrastructure
Phishing
Backdoor / C2
Data Exfiltration
APT
cybercrime
financial-sector
malware
espionage

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
55%
Added
Jul 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.