GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
A Chinese cybercrime group, known as CylindricalCanine (a sub-group of GoldenEyeDog), has been linked to a significant security breach at DigiCert, a code-signing certificate provider. The attackers exploited a vulnerability within DigiCert's support portal, allowing them to steal code-signing certificates and use them to sign their own malware, specifically Golden Gh0st RAT. This campaign involved phishing emails and support portal submissions, resulting in the revocation of 60 compromised certificates and the deployment of the Gh0st RAT, which is used to steal data from various applications and services. The group has a history of targeting finance organizations in the Asia-Pacific region and has previously utilized similar techniques against the gambling industry.
A Chinese cybercrime group, known as CylindricalCanine (a sub-group of GoldenEyeDog), has been linked to a significant security breach at DigiCert, a code-signing certificate provider. The attackers exploited a vulnerability within DigiCert’s support portal, allowing them to steal code-signing certificates and use them to sign their own malware, specifically Golden Gh0st RAT. The campaign began with phishing emails containing files disguised as customer screenshots, which when clicked, downloaded additional payloads from an external server.
DigiCert’s support portal contained a function that allowed authenticated DigiCert support analysts to access customer accounts from the customer’s perspective to facilitate support tasks. The threat actor used this function to access initialization codes for orders that were approved but pending delivery for EV Code Signing certificate orders across a finite set of customer accounts. The fatal oversight was that the possession of an initialization code, coupled with an approved order, was ‘functionally sufficient’ to obtain EV Code Signing certificates across a set of customer accounts and CAs.
The company subsequently revoked 60 compromised certificates issued by the following CAs:
- DigiCert Trusted G4 Code Signing RSA4096 SHA256 2021 CA1
- DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
- GoGetSSL G4 CS RSA4096 SHA256 2022 CA-1
- Verokey High Assurance Secure Code EV
Of these, 27 were explicitly linked to the threat actor, and the exploited certificates were used to sign Zhong Stealer malware artifacts. DigiCert’s security team deployed a code change to mask initialization codes from proxied users on both E.U. and U.S. platforms using either the UI or API.
Golden Gh0st RAT is used primarily in phishing emails and/or submissions to support portals (these submissions may themselves be emails received by a ticketing system). The malware’s capabilities include setting up persistence, stealing sensitive data, starting a SOCKS proxy tunnel, suppressing display output, logging keystrokes, taking screenshots, enumerating processes, executing shell commands, dropping additional payloads, and clearing Windows Event logs. The malware specifically targets applications such as Skype, Google Chrome, Mozilla Firefox, 360 Secure Browser, 360 Speed Browser, and Tencent QQ Browser.
This campaign aligns with other known activities by CylindricalCanine, a group linked to the GoldenEyeDog operation, which has previously targeted finance organizations in the Asia-Pacific region and utilized similar techniques against the gambling industry. The group has a history of using similar tactics to other Chinese cybercrime groups, including Silver Fox and Black Basta.
