Skip to content
Data Breach

GoldenEyeDog Hackers Group Behind DigiCert Breach that Hijacks Code-Signing Certificates

GoldenEyeDog, a Chinese cybercrime group linked to the Golden Gh0st malware family, is back in focus after an intrusion at DigiCert exposed the risks around code-signing certificates. The attackers used the access to intercept customer certificate activation codes and sign their own malicious files....

· Jul 20, 2026 · 6 min read · 👁 6 views
GoldenEyeDog Hackers Group Behind DigiCert Breach that Hijacks Code-Signing Certificates

GoldenEyeDog, a Chinese cybercrime group linked to the Golden Gh0st malware family, is back in focus after an intrusion at DigiCert exposed the risks around code-signing certificates.

The attackers used the access to intercept customer certificate activation codes and sign their own malicious files.

The operation relied on a simple but effective route into a sensitive environment.

Malicious files were disguised as screenshots, delivered through phishing emails or support-ticket submissions, and opened by staff who believed they were reviewing customer content.

Expel said in a report shared with Cyber Security News (CSN) that the activity was carried out by a GoldenEyeDog subgroup it calls CylindricalCanine.

Researchers linked the group to Golden Gh0st Loader and Golden Gh0st RAT, malware tools that have evolved through several campaigns since 2015.

Golden Gh0st RAT infection chain (Source - Expel)
Golden Gh0st RAT infection chain (Source – Expel)

The case also highlights a larger problem for defenders. A valid code-signing certificate can make a malicious program appear more trustworthy to Windows security checks, allowing attackers to gain an advantage before detection tools or users recognize the danger.

GoldenEyeDog Hackers Group Behind DigiCert Breach

The April 2026 breach began when a DigiCert support employee ran a malicious file received through the company’s ticketing system.

The compromised device gave the attackers access to initialization codes associated with customers renewing code-signing certificates.

Those codes are used to activate the hardware tokens required for signing software. By stealing them, the attackers could intercept certificates intended for legitimate customers, then use them to sign malware that looked more credible to security controls.

Earlier reporting on the weaponized screensaver DigiCert breach documented how the incident involved malware previously tracked as Zhong Stealer.

Expel’s analysis indicates that the malware is more than an information stealer. Golden Gh0st RAT can give operators remote access, collect browser credentials, capture screenshots, list running processes, execute commands, and erase traces of activity from infected systems.

The RAT also supports persistence, meaning it can remain active after a reboot.

One observed plugin created a backdoor account with administrator privileges and altered system settings to enable remote desktop access, giving attackers another way to return to a compromised device.

Loader Tactics and Detection

Golden Gh0st Loader commonly uses DLL sideloading, a technique in which a legitimate Windows application is tricked into loading a malicious library placed beside it. The library then decrypts and loads the actual RAT from a file that may be disguised as a log file.

That approach makes the infection chain harder to spot because trusted applications can be used as part of the execution process.

Qi’anxin’s depiction of the infection chain associated with GoldenEyeDog’s watering hole lures (Source - Expel)
Qi’anxin’s depiction of the infection chain associated with GoldenEyeDog’s watering hole lures (Source – Expel)

Similar abuse has appeared in the recent AsyncRAT sideloading campaign, where attackers hid malicious activity behind apparently normal software components.

In the recent campaign, the loader retrieved additional files from cloud-hosted locations, including a legitimate executable, supporting runtime files, a malicious DLL, an encrypted payload, and decoy documents.

A fake image or PDF displaying a 503 error helped make the activity appear less suspicious to victims.

Golden Gh0st RAT communicates with its command-and-control servers through unencrypted WebSocket connections, while encrypting the content inside those connections.

Analysts observed the malware using low-numbered ports 5188 and 5198, which can help defenders investigate unusual outbound traffic.

Security teams should closely validate attachments and download links submitted through support portals, especially files presented as screenshots or customer evidence.

Staff handling tickets should use isolated review systems where possible and verify unexpected files through a separate channel before opening them.

Defenders should also watch for suspicious DLLs loaded by legitimate applications, unexpected scheduled tasks, new local administrator accounts, and outbound WebSocket traffic to the listed domains.

Monitoring for the encrypted RAT command traffic and applying network detections for Golden Gh0st’s distinctive communications can improve the chance of catching the activity early.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
File name20241224.exeFirst-stage executable, presented as a photo-themed file
URLhxxps://kkuu.oss-cn-hongkong.aliyuncs.com/ss/uu.txtConfiguration file URL used by the 2025 loader
URLhxxps://kkuu.oss-cn-hongkong.aliyuncs.com/ss/down.exeSecond-stage executable download
File namedown.exeDownloaded executable used in the 2025 infection chain
SHA-2564eaebd93e23be3427d4c1349d64bef4b5fc455c93aebb9b5b752981e9266488eHash for down.exe
URLhxxps://kkuu.oss-cn-hongkong.aliyuncs.com/ss/TASLoginBase.dllMalicious DLL download
File nameTASLoginBase.dllDLL used for sideloading
SHA-2561abffe97aafe9916b366da57458a78338598cab9742c2d9e03e4ad0ba11f29bfHash for TASLoginBase.dll
URLhxxps://kkuu.oss-cn-hongkong.aliyuncs.com/ss/TASLogin.logEncrypted RAT payload download
File nameTASLogin.logEncrypted payload loaded by the sideloaded DLL
SHA-256dd44dabff536a1aa9b845dd891ad483162d4f28913344c93e5d59f648a186098Hash for TASLogin.log
URLhxxps://storage.googleapis.com/kiki001/as.txtConfiguration file URL used in the June 2026 campaign
URLhxxps://storage.googleapis.com/kiki001/updat.exeLegitimate executable used for sideloading
File nameupdat.exeLegitimate executable used to load the malicious DLL
SHA-2562b0071007c3f5fa8e949a8de53be03e97901dd505694ca939b575a49e4fdbdbbHash for updat.exe
URLhxxps://storage.googleapis.com/kiki001/vcruntime140.dllRuntime library download
File namevcruntime140.dllLegitimate Microsoft runtime
SHA-2568e08575492175e042f093f325b07a5c14ca71e7c581474838db3d48f5aab1312Hash for vcruntime140.dll
URLhxxps://storage.googleapis.com/kiki001/msvcp140.dllRuntime library download
File namemsvcp140.dllLegitimate Microsoft runtime
SHA-256e4c71980dbb4a1e1a86816687afdaea043b639b531135fc4516fb2429fe623fcHash for msvcp140.dll
URLhxxps://storage.googleapis.com/kiki001/crashreport.dllMalicious DLL download
File namecrashreport.dllMalicious DLL used for sideloading
SHA-25627b722c66f69e360c4da106daacf3b9eeaabd20634d7e5eff45a28bd70ebfd65Hash for crashreport.dll
URLhxxps://storage.googleapis.com/kiki001/updat.logEncrypted payload download
File nameupdat.logEncrypted payload loaded into memory
SHA-2563313f347e83aaf48ea31fb1d49fc37452f48f81d20a1b93009e2e78385ff4bbaHash for updat.log
URLhxxps://storage.googleapis.com/kiki001/image.jpgDecoy JPEG URL
File nameimage.jpgDecoy file displaying a 503 error
URLhxxps://storage.googleapis.com/kiki001/newimage.pdfDecoy PDF URL
File namenewimage.pdfDecoy PDF containing a 503-error image
SHA-256f67de637fca127212dc60b9a02f74e66dbd602b3b9f6f6e4f2b75614c1f9e944Hash for newimage.pdf
SHA-25681e276aaa3eb9b3f595663c316b3c6414cc3dde5e6cc3a82856b7276acabb7deGolden Gh0st RAT sample observed April 12, 2026
Domain and portuu.goldeyeuu.io:5188Golden Gh0st RAT command-and-control server
Domain and portwk.goldeyeuu.io:5188Golden Gh0st RAT command-and-control server
Domain and portapi.keensie.com:5198Golden Gh0st RAT command-and-control server
File nameplugin32.dllPersistence plugin that deploys an RDP backdoor
SHA-256d1b1938963037aa332591a4c999523a05886d1f62d80e03f0adc22630b8671c4Hash for the decrypted and unpacked plugin32.dll payload
Encryption key8A913610E905C3DD1F657811EA3B1933471B230F88E1C155616099A03AB0ABC0Hardcoded Golden Gh0st RAT REGISTERKEY
Encryption key2031A71C399563ADAF1572E10ABB395387EB132208A001C5E140496D7A3E0B26Hardcoded Golden Gh0st RAT MODULEKEY

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Recommended for you