← Back to Tech & Science

Chinese Cyber Group CylindricalCanine Breaches DigiCert to Steal Code-Signing Certificates

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

SAN FRANCISCO — A subgroup of the Chinese cybercrime organization GoldenEyeDog, identified as CylindricalCanine, successfully breached certificate authority DigiCert in early April 2026, stealing code-signing credentials to legitimize a new wave of malware targeting financial institutions across Asia-Pacific.

The intrusion occurred on April 2, 2026. Security researchers confirmed that the threat actors gained unauthorized access to DigiCert's systems and exfiltrated valid digital certificates. These stolen assets were immediately deployed by CylindricalCanine to sign a variant of Zhong Stealer malware, allowing the malicious software to bypass security controls on victim machines by appearing as trusted code.

CylindricalCanine operates under the broader GoldenEyeDog umbrella, a group historically linked to state-sponsored espionage and financial theft. The specific objective of this operation was to acquire legitimate signing certificates that could mask their operations from antivirus solutions and endpoint detection systems. By utilizing DigiCert's credentials, the attackers ensured their Zhong Stealer payload would execute without triggering standard security alerts on compromised networks.

The malware campaign is specifically directed at finance organizations within the Asia-Pacific region. The use of stolen code-signing certificates represents a significant escalation in sophistication for the group, as it allows them to infiltrate high-security environments that typically rely heavily on certificate validation for software integrity. Once executed, Zhong Stealer is designed to harvest sensitive data, including banking credentials and personal identification information.

DigiCert has not publicly detailed the full scope of the breach or confirmed whether other certificates were compromised beyond those used in this specific campaign. The company's internal response mechanisms remain undisclosed as investigators work to contain the incident and assess potential lateral movement within their infrastructure.

The theft highlights a growing trend among advanced persistent threat groups targeting certificate authorities directly rather than attempting to forge digital signatures. By compromising trusted issuers, attackers can create malware that is indistinguishable from legitimate software updates or applications until it executes its payload on an endpoint.

Questions remain regarding the total number of certificates stolen and whether CylindricalCanine has distributed additional variants of Zhong Stealer using other compromised credentials. Security firms are monitoring traffic patterns in the Asia-Pacific financial sector for signs of further activity, while DigiCert works to revoke affected certificates and patch vulnerabilities exploited during the April 2 intrusion.

Discussion

0 / 2000