
APT Lures Shift to Jobs, Code Reviews, Cloud Apps
This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…
Researchers linked DigiCert’s April 2026 breach to a GoldenEyeDog sub-group that tricked support staff into running a malicious file delivered through a customer support chat. The attackers then abused DigiCert’s support portal features to intercept EV code-signing certificate “initialization codes,” enabling them to obtain and misuse customer certificates to sign malware and evade detection.
The intrusion began in a customer support chat channel rather than an inbox. A threat actor contacted DigiCert's support team and delivered a ZIP file disguised as a customer screenshot. Instead of an image, the file contained a .scr executable carrying a malicious payload. Once opened by a support analyst, the malware gave the attacker a foothold on that employee's device and, from there, access into DigiCert's internal support portal.
From inside the portal, the attacker was able to view EV code-signing certificate initialization codes tied to approved-but-pending orders. That access let them obtain and misuse customer certificates, ultimately using some of them to sign malware, including artifacts linked to Zhong Stealer, so the malicious files would appear trustworthy and evade detection. Researchers at Expel attributed the activity to a cluster called CylindricalCanine, described as a sub-group of GoldenEyeDog, and connected the tooling to Golden Gh0st RAT.
The pretext relied on a routine, low-friction interaction: a customer sharing a screenshot in a support conversation. Support staff are trained to be responsive and helpful, and reviewing an attached file from someone claiming to be a customer is a normal part of that job. The disguise worked because the file type mismatch, a ZIP containing an executable rather than an image, was not an obvious red flag in the flow of a busy support queue.
The impact was amplified by portal features that let authenticated support analysts act on behalf of customer accounts. That capability, useful for legitimate support work, also meant a single compromised analyst session could expose sensitive data like certificate initialization codes.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
A threat actor contacted DigiCert's support team through a customer chat channel and delivered a ZIP file disguised as a customer screenshot. The file actually contained a .scr executable with a malicious payload.
They abused DigiCert's support portal features to view and intercept EV code-signing certificate initialization codes for approved-but-pending orders, then used those to obtain and misuse customer certificates.
DigiCert revoked 60 certificates, with 27 explicitly linked to the threat actor, and some were used to sign Zhong Stealer malware artifacts to help it evade detection.
Expel noted the same group, tracked as CylindricalCanine (a GoldenEyeDog sub-group), also distributes files disguised as screenshots through phishing emails and support portal submissions.
In April 2026, DigiCert got breached because someone opened a fake “screenshot” ZIP sent in a support chat. The ZIP hid a .scr executable with malware. Once it ran, GoldenEyeDog’s CylindricalCanine group used it to get into DigiCert’s support portal and intercept EV code-signing initialization codes. Here’s the twist: those stolen EV certs were used to sign Zhong Stealer malware, so the files looked trusted. And CylindricalCanine doesn’t just use chat – they also send “screenshot” links in phishing emails that download more payloads. Your move: if someone sends a “screenshot” as a ZIP, .scr, or any executable in chat or email, don’t open it, tell them we only accept screenshots as image uploads, then report it to security.

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…

Researchers report multiple real-world email phishing campaigns that used tax and government-benefit themes to trick people into downloading malware. The…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

Researchers reported an active PhantomEnigma campaign where attackers hijacked 20+ Brazilian government websites and used them as trusted stepping-stones to…

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude…

AI firm ORO says a suspected North Korean attacker hijacked a real conference contact’s Telegram account and lured an employee into joining a fake Microsoft…