1mo ago · hacker-news
A threat actor cluster known as CylindricalCanine, linked to the broader GoldenEyeDog (APT-Q-27) group, was responsible for a breach at DigiCert in April 2026. The attackers compromised support analysts via a malicious .scr file delivered through a customer support chat, gaining access to initialization codes and stealing code-signing certificates. These certificates were then used to sign malware, including Zhong Stealer and Golden Gh0st RAT, enabling evasion of security detection. The group primarily targets finance organizations in the Asia-Pacific region using phishing and DLL side-loading techniques.