GoldenEyeDog
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
GoldenEyeDog is a threat actor tracked under that alias, with publicly available information indicating the actor is based in China. The actor came to attention in early April 2026 when a malicious payload delivered through a customer chat service compromised two support endpoints of DigiCert, allowing the intruders to reach the company's internal support portal. Inside the portal they obtained initialization codes for approved extended‑validation code‑signing orders, which they then used to acquire legitimate code‑signing certificates. Those certificates were subsequently employed to sign the Zhong Stealer malware, enabling the malware to appear trusted to security tools. The activity was first reported by SecurityWeek and BleepingComputer, which provided details on the compromised chat service and the subsequent certificate misuse.
In response, DigiCert revoked sixty certificates, twenty‑seven of which were linked to the actor and eleven that were flagged by the security community as malicious. Shortly after the revocation, Microsoft Defender produced a false positive, labeling DigiCert’s root certificates as Trojan:Win32/Cerdigent.A!dha; the error was corrected in a later security intelligence update. The incident demonstrates the actor’s ability to exploit customer‑support channels to gain privileged access to a certificate authority’s internal systems. The observed tactics include delivering a malicious payload via chat, moving laterally to a support portal, and extracting code‑signing initialization material. The actor’s tooling appears focused on abusing legitimate code‑signing infrastructure rather than deploying custom malware families, with the Zhong Stealer being the only malware explicitly tied to the operation. The case underscores how compromising a certificate authority’s support infrastructure can undermine the trust model of code signing. Defender’s false positive illustrates how revoked or suspicious certificates can trigger detection rules that affect legitimate assets. No additional campaigns or public attributions linking GoldenEyeDog to a state sponsor, criminal consortium, or other geographic targets have been disclosed in open sources. Consequently, the available public record limits the profile to the single verified operation described above.
Incidents
Attributed incidents are available to members.
1 incident