The recent DigiCert breach, attributed to the threat activity cluster CylindricalCanine, has shed light on the evolving tactics of Chinese cybercrime groups. This incident highlights the group's ability to exploit code-signing certificates and the potential implications for the security of digital signatures.
CylindricalCanine, a subgroup of GoldenEyeDog (APT-Q-27), has been linked to the April 2026 DigiCert security incident. The group's primary tactic involves distributing files disguised as screenshots in phishing emails, leading to a DLL side-loading chain and ultimately deploying Golden Gh0st RAT. This malware is a modified version of Gh0st RAT, a remote access trojan (RAT) widely used by Chinese hacking groups.
The attack chain begins with a ZIP file disguised as a customer screenshot, delivered via a customer chat channel. Upon execution, the file contains a .scr executable with a malicious payload. The threat actor leverages a limited function within the customer-support portal to access initialization codes for approved but pending delivery EV Code Signing certificate orders. This access allows the actor to obtain certificates across a set of customer accounts and CAs, which are then weaponized to sign Zhong Stealer malware artifacts.
The DigiCert compromise revealed a fatal oversight in the company's security measures. The possession of an initialization code, coupled with an approved order, was functionally sufficient to obtain certificates. DigiCert revoked 60 certificates issued by various CAs, 27 of which were explicitly linked to the threat actor. The company has since deployed a code change to mask initialization codes from proxied users on both E.U. and U.S. platforms.
This incident underscores the importance of robust security measures, especially for code-signing certificate providers. The use of Golden Gh0st RAT, with its wide array of capabilities, including data collection and persistence, highlights the need for organizations to stay vigilant against sophisticated cyber threats. As Chinese cybercrime groups continue to evolve their tactics, the security community must adapt and enhance its defenses to protect against such attacks.