Fake Screenshot ZIP Led to DigiCert Cert Theft

The Hacker News · High sophistication
Last updated July 30, 2026

Researchers linked DigiCert’s April 2026 breach to a GoldenEyeDog sub-group that tricked support staff into running a malicious file delivered through a customer support chat. The attackers then abused DigiCert’s support portal features to intercept EV code-signing certificate “initialization codes,” enabling them to obtain and misuse customer certificates to sign malware and evade detection.

How the attack worked

The intrusion began in a customer support chat channel rather than an inbox. A threat actor contacted DigiCert's support team and delivered a ZIP file disguised as a customer screenshot. Instead of an image, the file contained a .scr executable carrying a malicious payload. Once opened by a support analyst, the malware gave the attacker a foothold on that employee's device and, from there, access into DigiCert's internal support portal.

From inside the portal, the attacker was able to view EV code-signing certificate initialization codes tied to approved-but-pending orders. That access let them obtain and misuse customer certificates, ultimately using some of them to sign malware, including artifacts linked to Zhong Stealer, so the malicious files would appear trustworthy and evade detection. Researchers at Expel attributed the activity to a cluster called CylindricalCanine, described as a sub-group of GoldenEyeDog, and connected the tooling to Golden Gh0st RAT.

Why it succeeded

The pretext relied on a routine, low-friction interaction: a customer sharing a screenshot in a support conversation. Support staff are trained to be responsive and helpful, and reviewing an attached file from someone claiming to be a customer is a normal part of that job. The disguise worked because the file type mismatch, a ZIP containing an executable rather than an image, was not an obvious red flag in the flow of a busy support queue.

The impact was amplified by portal features that let authenticated support analysts act on behalf of customer accounts. That capability, useful for legitimate support work, also meant a single compromised analyst session could expose sensitive data like certificate initialization codes.

What to watch for

  • A

Key findings

  • Attackers contacted DigiCert support through a customer chat channel and sent a ZIP file disguised as a screenshot; it contained a .scr executable with a malicious payload.
  • The compromise enabled unauthorized access to DigiCert’s internal support portal and the viewing/interception of EV code-signing certificate initialization codes for approved-but-pending orders.
  • DigiCert revoked 60 certificates; 27 were explicitly linked to the threat actor, and some were used to sign “Zhong Stealer” malware artifacts.
  • Expel attributed the activity cluster “CylindricalCanine” to a sub-group of GoldenEyeDog, and connected it to Golden Gh0st RAT tooling and delivery tactics.
  • Expel noted similar delivery methods via phishing emails and/or support portal submissions, often using files disguised as screenshots and link-based payload delivery.

Who’s being targeted

  • Commonly targeted roles: Customer Support, Service Desk / Helpdesk, IT Operations, Security Operations, Identity & Access Management (IAM), PKI / Certificate management teams, Finance teams (APAC-focused per targeting note).
  • Affected industries: Certificate authorities / trust services, Cybersecurity / IT security services, Customer support operations, Finance organizations (Asia-Pacific region), Gambling and gaming sectors.
  • Attack channels: website, email.
  • Impersonated: DigiCert customer (via support chat), Unspecified sender posing as someone sharing a screenshot.

Red flags to watch for

  • A ZIP file sent through chat instead of an image upload
  • A “screenshot” that is actually an executable (.scr)
  • Unusual file type for a support screenshot
  • Message pushes you to click a link to retrieve a “screenshot”
  • Downloaded content pulls additional payloads from an external server
  • File-type mismatch (screenshot delivered as executable/installer rather than image)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did attackers gain access to DigiCert's support systems?

A threat actor contacted DigiCert's support team through a customer chat channel and delivered a ZIP file disguised as a customer screenshot. The file actually contained a .scr executable with a malicious payload.

What did the attackers do once inside?

They abused DigiCert's support portal features to view and intercept EV code-signing certificate initialization codes for approved-but-pending orders, then used those to obtain and misuse customer certificates.

Were the stolen certificates used for anything specific?

DigiCert revoked 60 certificates, with 27 explicitly linked to the threat actor, and some were used to sign Zhong Stealer malware artifacts to help it evade detection.

Is this the same tactic used elsewhere?

Expel noted the same group, tracked as CylindricalCanine (a GoldenEyeDog sub-group), also distributes files disguised as screenshots through phishing emails and support portal submissions.

Read the video transcript

In April 2026, DigiCert got breached because someone opened a fake “screenshot” ZIP sent in a support chat. The ZIP hid a .scr executable with malware. Once it ran, GoldenEyeDog’s CylindricalCanine group used it to get into DigiCert’s support portal and intercept EV code-signing initialization codes. Here’s the twist: those stolen EV certs were used to sign Zhong Stealer malware, so the files looked trusted. And CylindricalCanine doesn’t just use chat – they also send “screenshot” links in phishing emails that download more payloads. Your move: if someone sends a “screenshot” as a ZIP, .scr, or any executable in chat or email, don’t open it, tell them we only accept screenshots as image uploads, then report it to security.

Similar attacks

Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Researchers described an active phishing campaign that tricks people with fake Adobe/Zoom update and “document review” themes to install the legitimate ScreenConnect remote-access tool. Once installed, attackers get persistent remote control of the victim’s computer while blending in as normal IT…

August 4, 2026
Tax and SSA Phish Push Cruciferra Malware Loader

Tax and SSA Phish Push Cruciferra Malware Loader

Researchers report multiple real-world email phishing campaigns that used tax and government-benefit themes to trick people into downloading malware. The campaigns used a “crypter” service called Cruciferra to hide malicious files and help malware run while avoiding detection. Targets included…

July 27, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
Hijacked .gov.br Sites Used as Malware Lures

Hijacked .gov.br Sites Used as Malware Lures

Researchers reported an active PhantomEnigma campaign where attackers hijacked 20+ Brazilian government websites and used them as trusted stepping-stones to deliver malware. The lure used official-looking police-themed documents (sometimes with QR codes) and emails that could pass common email…

July 16, 2026
Korea Flags Job-Offer Phish + Watering Holes

Korea Flags Job-Offer Phish + Watering Holes

South Korean agencies warned that a state-backed hacking group is actively targeting citizens and businesses using job-themed phishing emails and “watering hole” attacks on legitimate websites. The phishing lures include fake job applicants sending resume links and impersonated recruiters sending…

July 31, 2026
Fake Claude App and Alert Apps Drive New Scams

Fake Claude App and Alert Apps Drive New Scams

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude desktop app, a fake emergency alert app, and banking-malware phishing). The common pattern is “looks normal, feels urgent,” leading users to…

July 23, 2026