CSIDB logo
Incident

DigiCert

Incident posture

Attack window
Apr 2026
Location
United States of America
Status
Resolved
CIA posture
Available to members
Updated
2026-09-11 09:04

Linked entities

Victim
DigiCert
Threat actors
1 actor
Sources
2 sources

Timeline

Occurred
Apr 2026
Discovered
Apr 2026
Disclosed
May 2026
Resolved
Apr 2026

Summary

DigiCert disclosed that a malicious payload delivered through a customer chat channel compromised two endpoints in its support environment, allowing attackers to pivot to the internal support portal and obtain initialization codes for approved EV code‑signing certificate orders. Using those codes, the threat actor fraudulently obtained certificates, which were later revoked; the company reported revoking 60 certificates, 27 of them directly linked to the attacker and 11 associated with the Zhong Stealer malware family. The company stated that no other internal systems were misused and subsequently enhanced security controls, including multi‑factor authentication for administrative workflows, restrictions on file types in support chats, and improved logging.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On April 2 2026 a threat actor delivered a malicious payload to DigiCert’s support team through a customer chat channel, disguising the file as a screenshot and embedding it in a ZIP file. The malware infected two endpoints, with the first compromise identified on April 3 and the second not discovered until April 14 due to a malfunctioning security solution on that system. From the infected endpoints the attackers pivoted to DigiCert’s internal support portal, exploiting a feature that allows authenticated support analysts to proxy into customer accounts and access initialization codes for pending EV Code Signing certificate orders. By combining these initialization codes with approved orders the threat actor obtained EV Code Signing certificates for a finite set of customer accounts and certificate authorities. On April 17 DigiCert reported that it had identified and revoked 60 certificates linked to the incident, 27 of which were explicitly tied to the threat actor, and cancelled all pending orders within the relevant window to eliminate further access.

Of the revoked certificates, 11 were identified by the community and found to have been used to sign the Zhong Stealer malware family, while the remaining 16 were discovered during DigiCert’s own investigation. Security researchers including Squiblydoo, MalwareHunterTeam, and g0njxa had previously observed newly issued DigiCert EV certificates associated with companies such as Lenovo, Kingston, Shuttle Inc, and Palit Microsystems being used to sign malware, noting that these certificates were issued and used by the Chinese crime group #GoldenEyeDog (#APT‑Q‑27). The Zhong Stealer malware, described by analysts as more akin to a remote access trojan than a pure infostealer, was distributed via phishing emails containing fake images or screenshots, a first‑stage executable that displayed a decoy image, retrieval of a second‑stage payload from cloud storage such as AWS, and the use of signed binaries and loaders tied to legitimate vendors. DigiCert’s investigation found no evidence that the threat actor accessed other internal systems beyond the Code Signing initialization codes within the specific compromised accounts.

Beginning on April 30 2026 Microsoft Defender detections were updated to flag legitimate DigiCert root certificates as Trojan:Win32/Cerdigent.A!dha, resulting in widespread false‑positive alerts and the removal of those certificates from Windows trust stores on affected systems. The false positives were corrected in Security Intelligence update version 1.449.430.0, with the most recent update being 1.449.431.0, and the updated definitions automatically reinstall the previously removed certificates when users check for updates. Microsoft has not confirmed that the Defender detections are a consequence of the DigiCert incident, though the timing and focus on DigiCert‑related certificates have been noted as suggesting a possible connection; importantly, the certificates flagged by Defender are root certificates in the Windows trust store and do not match the revoked EV Code Signing certificates used to sign malware.

In response to the support portal breach DigiCert enforced multi‑factor authentication for administrative workflows, prevented proxied support users from accessing initialization codes, restricted the file types that could be transmitted via support chat and Salesforce case attachments, and improved logging across its environment. These measures were implemented after the revocation of the compromised certificates and the cancellation of pending orders, aiming to close the vectors that the threat actor had exploited. The company stated that all certificates potentially linked to the activity had been revoked by April 17 and that pending orders were cancelled to eliminate the attackers’ ability to obtain further certificates. No additional systems were found to have been compromised during the incident.

Sources

Sources available to members: 2 sources.

CSIDB