Also known as: header, tracked as, Broomstick, GoldenEyeDog, ProfSvc, Popa, services, other system resources, public key cryptography, one private, the file association, metamorphic, magic bytes, handler, Netshell, the IconEnvironmentDataBlock, mutating code
Chinese cybercrime group GoldenEyeDog has been active since 2015, regularly updating malware and leveraging code-signing certificates to bypass Windows SmartScreen since 2024. A subgroup called CylindricalCanine uses Golden Gh0st Loader and Golden Gh0st RAT, modified versions of the 2008 Gh0st RAT, primarily targeting finance organizations in the Asia Pacific region through phishing campaigns. In April 2026, these actors compromised a DigiCert support member's device and stole code-signing certificates intended for customers, which they used to sign their own malware. The malware uses DLL sideloading, custom WebSocket protocols for command and control, and includes capabilities for remote access, credential theft, keylogging, SOCKS proxy tunneling, and RDP backdoor creation. Analysis reveals consistent tactics including using legitimate executables to load malicious DLLs that decrypt payloads from files disguised as logs.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
CylindricalCanine, a subgroup of the Chinese cybercrime group GoldenEyeDog, is a sophisticated threat actor targeting financial organizations in the Asia Pacific region. Known for leveraging modified versions of the 2008 Gh0st RAT, such as Golden Gh0st Loader and RAT, this group has been active since 2015. In April 2026, they stole code-signing certificates from a DigiCert support member, enabling them to bypass Windows SmartScreen. Their malware includes capabilities for remote access, credential theft, keylogging, SOCKS proxy tunneling, and RDP backdoor creation.
Goals & Targeting
CylindricalCanine likely seeks financial gain, focusing on sectors with high economic value such as finance. Their targeting of financial organizations in the Asia Pacific region suggests a strategic focus on regions with significant financial activity and potentially weaker defenses. The group's use of stolen code-signing certificates indicates an aim to enhance their operational persistence and evade detection.
Enhanced Description
CylindricalCanine operates as part of the larger GoldenEyeDog cybercrime group and has targeted financial services globally. The subgroup primarily focuses on Asia Pacific regions, conducting phishing campaigns to distribute their malware. Since 2015, they have continuously updated their tools, including leveraging legitimate executables to load malicious DLLs, which decrypt payloads from files disguised as logs. In a notable incident in April 2026, the group compromised a DigiCert support member's device, stealing code-signing certificates. These certificates were used to sign their malware, further enhancing its evasion capabilities. The malware employs custom WebSocket protocols for command and control (C2), making it harder to detect. CylindricalCanine's activities highlight the growing sophistication of cybercriminal groups targeting financial institutions for potential monetary gains.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
CylindricalCanine's campaign patterns include phishing-based distribution of malware, leveraging stolen code-signing certificates for persistence. Their operational tempo suggests a focus on high-value targets in finance, particularly in the Asia Pacific region. Notable past operations include the April 2026 compromise of a DigiCert support member, highlighting their ability to exploit supply chain vulnerabilities.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the data due to clear descriptions of operations, TTPs, and tools. No gaps identified as the information provided is comprehensive.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
45
Tools
0
Campaigns
42
IOCs
0
Observed Data
13
Tactics