CylindricalCanine is drawing attention from cybersecurity researchers after being linked to the DigiCert incident in April 2026, in which attackers abused access to a support environment to steal customer code-signing certificates. According to The Hacker News and Expel analysis, this activity cluster is a branch of GoldenEyeDog, also known as APT-Q-27, Dragon Breath, or Miuuti Group.

Background
GoldenEyeDog is described as a Chinese-speaking cybercrime group active since at least 2015 and known for campaigns targeting gambling, online gaming, and financial sectors across the Asia-Pacific region. Its familiar approach is to build fake websites, send lure files, or abuse support channels to convince victims to open malware.
In the new profile, Expel named the related branch CylindricalCanine. What stands out is not only the malware, but the target: a digital certificate provider. When code-signing certificates are abused, malware can look more like legitimate software to users, operating systems, and some defensive layers.
Key Timeline
According to information DigiCert disclosed through Mozilla’s bug reporting ecosystem, on 02/04/2026 a threat actor contacted DigiCert support via customer chat and sent a ZIP file disguised as a screenshot. Inside was a .scr executable carrying a malicious payload.
After two support employees’ workstations were compromised, the attackers abused a support portal function that allowed staff to view accounts from the customer’s perspective when handling requests. From there, they accessed initialization codes for approved EV Code Signing orders that had not yet been fully delivered.
DigiCert later revoked 60 certificates, including 27 believed to be directly associated with the threat actor. The Hacker News cited information that the abused certificates were used to sign Zhong Stealersamples, a data-stealing malware family observed in earlier campaigns.
Tactics and Tools
CylindricalCanine is believed to use files disguised as screenshots in phishing emails or requests submitted to support systems. When a victim clicks the link or opens the file, an additional payload is downloaded from an external server, creating a foothold for follow-on activity.
Expel also linked this activity to Golden Gh0st RAT, a variant in the Gh0st RAT family that operates through plugins and an internal module orchestration mechanism. This model gives attackers more flexibility: they can collect system information, steal data, maintain access, or switch to another payload depending on the target.
Why Code-Signing Certificates Are High-Value Targets
A code-signing certificate is not decorative metadata for software. It is an important trust signal in the digital supply chain, helping verify the publisher and reduce warnings when software is distributed. If attackers possess a valid certificate, malware can bypass part of users’ natural caution and make life harder for defenses that rely mainly on file reputation.
The DigiCert incident shows that risk does not necessarily begin with breaking cryptographic algorithms. The weakness can sit in support workflows, internal access, portal design, and the assumption that an initialization code stored in a support system cannot become an operational key for attackers.
Implications for Enterprises
Technically, organizations should treat a digitally signed file as a signal that still needs verification, not absolute proof of safety. A file with a valid signature can still be malicious if the certificate was stolen, issued for the wrong purpose, or abused during the window before revocation.
Operationally, this incident puts significant pressure on certificate service providers, software vendors, and customer support teams. Internal portals should restrict sensitive data according to least privilege, fully log support staff activity, separate access by role, and re-evaluate flows that allow staff to “view as customer.”
Key Takeaways
The CylindricalCanine profile shows that a successful campaign can begin with something very ordinary: a fake screenshot file sent into a support channel. When social engineering, remote access malware, and a high-value target such as code-signing certificates are combined, the impact can spread to many organizations beyond the initial victim.
Enterprises should review file-handling policies in support departments, isolate environments used to open customer files, monitor abnormal activity involving code-signing certificates, and avoid dismissing alerts just because a file is signed. Digital trust remains durable only when technology, process, and people are all tightly controlled.
VNCyberS compiled from The Hacker News, Expel, DigiCert, and Mozilla Bugzilla















