{"id":1774,"date":"2026-07-18T07:22:37","date_gmt":"2026-07-18T00:22:37","guid":{"rendered":"https:\/\/vncybers.vn\/ho-so-cylindricalcanine-nhom-dung-sau-vu-danh-cap-chung-chi-digicert\/"},"modified":"2026-07-18T07:22:37","modified_gmt":"2026-07-18T00:22:37","slug":"cylindricalcanine-digicert-certificate-theft-profile","status":"publish","type":"post","link":"https:\/\/vncybers.vn\/en\/ho-so-cylindricalcanine-nhom-dung-sau-vu-danh-cap-chung-chi-digicert\/","title":{"rendered":"CylindricalCanine Profile: The Group Behind the DigiCert Certificate Theft"},"content":{"rendered":"<p><strong>CylindricalCanine<\/strong> is drawing attention from cybersecurity researchers after being linked to the DigiCert incident in April 2026, in which attackers abused access to a support environment to steal customer code-signing certificates. According to The Hacker News and Expel analysis, this activity cluster is a branch of <strong>GoldenEyeDog<\/strong>, also known as APT-Q-27, Dragon Breath, or Miuuti Group.<\/p>\n<p style=\"text-align: center;\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1200\" height=\"800\" src=\"https:\/\/vncybers.vn\/wp-content\/uploads\/2026\/07\/cylindricalcanine-inline.jpg\" alt=\"Chuy\u00ean gia b\u1ea3o m\u1eadt theo d\u00f5i r\u1ee7i ro ch\u1ee9ng ch\u1ec9 k\u00fd m\u00e3 trong m\u00f4i tr\u01b0\u1eddng doanh nghi\u1ec7p\" class=\"wp-image-1773\" style=\"max-width: 100%; height: auto;\" srcset=\"https:\/\/vncybers.vn\/wp-content\/uploads\/2026\/07\/cylindricalcanine-inline.jpg 1200w, https:\/\/vncybers.vn\/wp-content\/uploads\/2026\/07\/cylindricalcanine-inline-300x200.jpg 300w, https:\/\/vncybers.vn\/wp-content\/uploads\/2026\/07\/cylindricalcanine-inline-1024x683.jpg 1024w, https:\/\/vncybers.vn\/wp-content\/uploads\/2026\/07\/cylindricalcanine-inline-768x512.jpg 768w\" sizes=\"(max-width: 1200px) 100vw, 1200px\" \/><\/p>\n<h2>Background<\/h2>\n<p>GoldenEyeDog is described as a Chinese-speaking cybercrime group active since at least 2015 and known for campaigns targeting gambling, online gaming, and financial sectors across the Asia-Pacific region. Its familiar approach is to build fake websites, send lure files, or abuse support channels to convince victims to open malware.<\/p>\n<p>In the new profile, Expel named the related branch CylindricalCanine. What stands out is not only the malware, but the target: a digital certificate provider. When code-signing certificates are abused, malware can look more like legitimate software to users, operating systems, and some defensive layers.<\/p>\n<h2>Key Timeline<\/h2>\n<p>According to information DigiCert disclosed through Mozilla\u2019s bug reporting ecosystem, on 02\/04\/2026 a threat actor contacted DigiCert support via customer chat and sent a ZIP file disguised as a screenshot. Inside was a <strong>.scr<\/strong> executable carrying a malicious payload.<\/p>\n<p>After two support employees\u2019 workstations were compromised, the attackers abused a support portal function that allowed staff to view accounts from the customer\u2019s perspective when handling requests. From there, they accessed initialization codes for approved EV Code Signing orders that had not yet been fully delivered.<\/p>\n<p>DigiCert later revoked 60 certificates, including 27 believed to be directly associated with the threat actor. The Hacker News cited information that the abused certificates were used to sign <strong>Zhong Stealer<\/strong>samples, a data-stealing malware family observed in earlier campaigns.<\/p>\n<h2>Tactics and Tools<\/h2>\n<p>CylindricalCanine is believed to use files disguised as screenshots in phishing emails or requests submitted to support systems. When a victim clicks the link or opens the file, an additional payload is downloaded from an external server, creating a foothold for follow-on activity.<\/p>\n<p>Expel also linked this activity to <strong>Golden Gh0st RAT<\/strong>, a variant in the Gh0st RAT family that operates through plugins and an internal module orchestration mechanism. This model gives attackers more flexibility: they can collect system information, steal data, maintain access, or switch to another payload depending on the target.<\/p>\n<h2>Why Code-Signing Certificates Are High-Value Targets<\/h2>\n<p>A code-signing certificate is not decorative metadata for software. It is an important trust signal in the digital supply chain, helping verify the publisher and reduce warnings when software is distributed. If attackers possess a valid certificate, malware can bypass part of users\u2019 natural caution and make life harder for defenses that rely mainly on file reputation.<\/p>\n<p>The DigiCert incident shows that risk does not necessarily begin with breaking cryptographic algorithms. The weakness can sit in support workflows, internal access, portal design, and the assumption that an initialization code stored in a support system cannot become an operational key for attackers.<\/p>\n<h2>Implications for Enterprises<\/h2>\n<p>Technically, organizations should treat a digitally signed file as a signal that still needs verification, not absolute proof of safety. A file with a valid signature can still be malicious if the certificate was stolen, issued for the wrong purpose, or abused during the window before revocation.<\/p>\n<p>Operationally, this incident puts significant pressure on certificate service providers, software vendors, and customer support teams. Internal portals should restrict sensitive data according to least privilege, fully log support staff activity, separate access by role, and re-evaluate flows that allow staff to \u201cview as customer.\u201d<\/p>\n<h2>Key Takeaways<\/h2>\n<p>The CylindricalCanine profile shows that a successful campaign can begin with something very ordinary: a fake screenshot file sent into a support channel. When social engineering, remote access malware, and a high-value target such as code-signing certificates are combined, the impact can spread to many organizations beyond the initial victim.<\/p>\n<p>Enterprises should review file-handling policies in support departments, isolate environments used to open customer files, monitor abnormal activity involving code-signing certificates, and avoid dismissing alerts just because a file is signed. Digital trust remains durable only when technology, process, and people are all tightly controlled.<\/p>\n<p style=\"text-align: right; margin-top: 40px;\"><em><strong>VNCyberS<\/strong> compiled from The Hacker News, Expel, DigiCert, and Mozilla Bugzilla<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>CylindricalCanine, a branch of GoldenEyeDog, has been linked to the DigiCert code-signing certificate theft and abuse to sign Zhong Stealer malware.<\/p>","protected":false},"author":2,"featured_media":1772,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[70],"tags":[409,412,406,403,405,410,408,404,413,411,38,407],"class_list":["post-1774","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ho-so","tag-apt-q-27","tag-chung-chi-ky-ma","tag-code-signing-certificate","tag-cylindricalcanine","tag-digicert","tag-dragon-breath","tag-golden-gh0st-rat","tag-goldeneyedog","tag-ho-so-an-ninh-mang","tag-miuuti-group","tag-phishing","tag-zhong-stealer"],"_links":{"self":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts\/1774","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/comments?post=1774"}],"version-history":[{"count":0,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts\/1774\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/media\/1772"}],"wp:attachment":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/media?parent=1774"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/categories?post=1774"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/tags?post=1774"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}