Fake Screenshot ZIP Led to DigiCert Cert Theft

The Hacker News · High sophistication
Last updated July 30, 2026

Researchers linked DigiCert’s April 2026 breach to a GoldenEyeDog sub-group that tricked support staff into running a malicious file delivered through a customer support chat. The attackers then abused DigiCert’s support portal features to intercept EV code-signing certificate “initialization codes,” enabling them to obtain and misuse customer certificates to sign malware and evade detection.

How the attack worked

The intrusion began in a customer support chat channel rather than an inbox. A threat actor contacted DigiCert's support team and delivered a ZIP file disguised as a customer screenshot. Instead of an image, the file contained a .scr executable carrying a malicious payload. Once opened by a support analyst, the malware gave the attacker a foothold on that employee's device and, from there, access into DigiCert's internal support portal.

From inside the portal, the attacker was able to view EV code-signing certificate initialization codes tied to approved-but-pending orders. That access let them obtain and misuse customer certificates, ultimately using some of them to sign malware, including artifacts linked to Zhong Stealer, so the malicious files would appear trustworthy and evade detection. Researchers at Expel attributed the activity to a cluster called CylindricalCanine, described as a sub-group of GoldenEyeDog, and connected the tooling to Golden Gh0st RAT.

Why it succeeded

The pretext relied on a routine, low-friction interaction: a customer sharing a screenshot in a support conversation. Support staff are trained to be responsive and helpful, and reviewing an attached file from someone claiming to be a customer is a normal part of that job. The disguise worked because the file type mismatch, a ZIP containing an executable rather than an image, was not an obvious red flag in the flow of a busy support queue.

The impact was amplified by portal features that let authenticated support analysts act on behalf of customer accounts. That capability, useful for legitimate support work, also meant a single compromised analyst session could expose sensitive data like certificate initialization codes.

What to watch for

  • A

Key findings

  • Attackers contacted DigiCert support through a customer chat channel and sent a ZIP file disguised as a screenshot; it contained a .scr executable with a malicious payload.
  • The compromise enabled unauthorized access to DigiCert’s internal support portal and the viewing/interception of EV code-signing certificate initialization codes for approved-but-pending orders.
  • DigiCert revoked 60 certificates; 27 were explicitly linked to the threat actor, and some were used to sign “Zhong Stealer” malware artifacts.
  • Expel attributed the activity cluster “CylindricalCanine” to a sub-group of GoldenEyeDog, and connected it to Golden Gh0st RAT tooling and delivery tactics.
  • Expel noted similar delivery methods via phishing emails and/or support portal submissions, often using files disguised as screenshots and link-based payload delivery.

Who’s being targeted

  • Commonly targeted roles: Customer Support, Service Desk / Helpdesk, IT Operations, Security Operations, Identity & Access Management (IAM), PKI / Certificate management teams, Finance teams (APAC-focused per targeting note).
  • Affected industries: Certificate authorities / trust services, Cybersecurity / IT security services, Customer support operations, Finance organizations (Asia-Pacific region), Gambling and gaming sectors.
  • Attack channels: website, email.
  • Impersonated: DigiCert customer (via support chat), Unspecified sender posing as someone sharing a screenshot.

Red flags to watch for

  • A ZIP file sent through chat instead of an image upload
  • A “screenshot” that is actually an executable (.scr)
  • Unusual file type for a support screenshot
  • Message pushes you to click a link to retrieve a “screenshot”
  • Downloaded content pulls additional payloads from an external server
  • File-type mismatch (screenshot delivered as executable/installer rather than image)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did attackers gain access to DigiCert's support systems?

A threat actor contacted DigiCert's support team through a customer chat channel and delivered a ZIP file disguised as a customer screenshot. The file actually contained a .scr executable with a malicious payload.

What did the attackers do once inside?

They abused DigiCert's support portal features to view and intercept EV code-signing certificate initialization codes for approved-but-pending orders, then used those to obtain and misuse customer certificates.

Were the stolen certificates used for anything specific?

DigiCert revoked 60 certificates, with 27 explicitly linked to the threat actor, and some were used to sign Zhong Stealer malware artifacts to help it evade detection.

Is this the same tactic used elsewhere?

Expel noted the same group, tracked as CylindricalCanine (a GoldenEyeDog sub-group), also distributes files disguised as screenshots through phishing emails and support portal submissions.

Read the video transcript

In April 2026, DigiCert got breached because someone opened a fake “screenshot” ZIP sent in a support chat. The ZIP hid a .scr executable with malware. Once it ran, GoldenEyeDog’s CylindricalCanine group used it to get into DigiCert’s support portal and intercept EV code-signing initialization codes. Here’s the twist: those stolen EV certs were used to sign Zhong Stealer malware, so the files looked trusted. And CylindricalCanine doesn’t just use chat – they also send “screenshot” links in phishing emails that download more payloads. Your move: if someone sends a “screenshot” as a ZIP, .scr, or any executable in chat or email, don’t open it, tell them we only accept screenshots as image uploads, then report it to security.

Similar attacks

Fake Recruiters & Cloud Email Fuel New Phishing

Fake Recruiters & Cloud Email Fuel New Phishing

This roundup describes real-world social engineering where attackers impersonate recruiters on LinkedIn and lure developers into running “coding tests” that install malware. It also outlines active phishing campaigns that abuse trusted cloud services (Google, AWS, Azure, Cloudflare) to send…

September 2, 2026
Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Researchers say the North Korea-linked Lazarus group ran “Operation Dream Job,” posing as recruiters and sending fake job offers to lure targets into downloading trojanized PDF tools and opening booby-trapped PDFs. The campaign focused largely on defense-related organizations and used both a…

August 12, 2026
Phishing PDF Drops Malware Via Fake Edge Loader

Phishing PDF Drops Malware Via Fake Edge Loader

Researchers describe BraZetsu, a Windows malware framework used by an initial-access broker to turn infected PCs into "access for sale" on a criminal marketplace. While the malware itself is technical, the article includes real-world delivery details pointing to phishing: victims are tricked into…

September 3, 2026
AI Voice “Apple Support” Phishing + Fake IT Helpdesk

AI Voice “Apple Support” Phishing + Fake IT Helpdesk

This news roundup describes real social-engineering operations where attackers impersonate trusted support teams to trick people into giving up secrets. One campaign uses email/SMS/WhatsApp plus AI voice calls pretending to be Apple Support to steal iPhone passcodes, while another uses phishing…

August 27, 2026
DEF CON Phish Uses Fake Coindesk VP + Google Doc

DEF CON Phish Uses Fake Coindesk VP + Google Doc

A real phishing campaign is targeting DEF CON speakers and attendees through X/Twitter messages pretending to be a Coindesk executive. Victims are sent to a Google document that attempts a “click-fix” trick to get them to paste malicious commands into a terminal or download malware. The goal is to…

August 21, 2026
Lazarus Lures Staff With Fake Jobs to Drop Malware

Lazarus Lures Staff With Fake Jobs to Drop Malware

Researchers tied North Korea’s Lazarus Group to a real-world campaign that approaches professionals with convincing fake recruiter outreach and job offers. Victims are tricked into opening a malicious PDF or installing a fake PDF viewer from lookalike websites, which then installs backdoors and can…

August 12, 2026