Skip to main content
Back to overview
High

DigiCert Security Incident Linked to GoldenEyeDog Subgroup CylindricalCanine

DigiCert's security incident in April 2026 has been attributed to CylindricalCanine, a subgroup of the China-linked cybercrime group GoldenEyeDog (also known as APT-Q-27, Dragon Breath, and Miuuti Group).

Key points

  • DigiCert's April 2026 security incident attributed to CylindricalCanine, a subgroup of GoldenEyeDog.
  • Attackers compromised a support employee's device via a phishing lure in a support ticket.
  • Initialization codes for code-signing certificates were stolen.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Phishing Social Engineering

Nation State Or Named Threat Actor actor profile

03

Potential impact

Potential fraud or account takeover risk

Impact remains under assessment

Published
Jul 23, 2026
Updated
Jul 25, 2026
Confidence
High
Evidence
10 sources

Structured assessment

Signal analysis

It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Nation State Or Named Threat Actor actor profile

Watch phishing, executive impersonation and account-takeover exposure.

  • Source type: possible insider or internal misuse
  • Actor profile: Nation State Or Named Threat Actor

Business impact

Potential fraud or account takeover risk
Impact area
Unknown

Mentioned entities

DigicertGoldenEyeDog Subgroup CylindricalCanine DigiCertCylindricalCanineChina-linkedGoldenEyeDogAPT-Q-27Dragon BreathMiuuti GroupDigiCertZong Stealer

Quick context

Questions about this signal

What happened in this signal?

DigiCert's security incident in April 2026 has been attributed to CylindricalCanine, a subgroup of the China-linked cybercrime group GoldenEyeDog (also known as APT-Q-27, Dragon Breath, and Miuuti Group). The attackers compromised a support employee's device using malware delivered via a phishing lure disguised as a screenshot or document sent through DigiCert's support-ticket workflow. This intrusion granted the threat actors access to initialization codes for customers renewing code-signing certificates. By intercepting these codes, the attackers were able to obtain 27 fraudulent code-signing certificates, which were then used to sign malware, including the "Zong Stealer" campaign. DigiCert identified the incident through third-party reports of certificates being used in malware and subsequently revoked 60 certificates by April 17, with 27 explicitly linked to the attackers. The company emphasized that its root certificates were never compromised, and the breach was limited to a finite set of certificates. DigiCert has since blocked high-risk file types at ingestion, removed malicious files from Salesforce cases and chat records, and is working on sandboxing controls for inbound support attachments.

When was this signal reported?

Shadow Tier lists Jul 23, 2026 as the signal date.

Which organization is connected to this signal?

Digicert is the organization connected to this public signal.

Explore Digicert
Which attack pattern is relevant?

This signal is connected to phishing and social-engineering intelligence based on its reported incident context.

Explore phishing and social-engineering intelligence