Chinese Cybercrime Group GoldenEyeDog Linked to DigiCert Breach and Certificate Theft

Cybersecurity researchers have linked the April 2026 security incident at certificate authority DigiCert to a Chinese cybercrime subgroup tracked as GoldenEyeDog, also known as CylindricalCanine. The intrusion resulted in the theft of code-signing certificates, which could be used to sign malicious software with trusted credentials.

Expel, the security firm that analyzed the incident, described the threat actor as a subgroup of GoldenEyeDog, a Chinese cybercrime collective known primarily for targeting the gambling and gaming sectors. The DigiCert breach represents a significant escalation in the group’s capabilities and ambitions, moving beyond its traditional focus areas into critical internet infrastructure.

Code-signing certificates are among the most valuable targets for cybercriminals because they allow malware to appear as legitimate software signed by a trusted authority. Operating systems and security software typically trust digitally signed code, making it far more likely that users will install malicious applications without suspicion.

The breach at DigiCert, one of the world’s largest certificate authorities, affected its infrastructure enough to disrupt normal operations and trigger an incident response process. Certificate authorities are considered critical infrastructure in the digital security ecosystem because they underpin the trust model that makes secure online communication possible.

DigiCert has not disclosed the full scope of the breach, but has confirmed that response measures included revoking potentially compromised certificates and notifying affected customers. Organizations that use DigiCert-issued certificates are advised to verify their certificate inventory and monitor for any unauthorized certificate requests.

This article was adapted from The Hacker News. Read the original here.