Home ยท Wiki ยท Entities & Threat Actors
type: entity ยท created: 2026-07-18 ยท updated: 2026-07-18 ยท tags: [apt-group, cybercrime-group, supply-chain] ยท confidence: medium ยท affected_sectors: [technology, government] ยท au_impact: false

CylindricalCanine

CylindricalCanine is a subgroup of the Chinese cybercrime group GoldenEyeDog (APT-Q-27). The subgroup was identified by Expel researchers in July 2026 as the perpetrator of the April 2026 DigiCert security incident.

Attribution

  • Parent group: GoldenEyeDog (APT-Q-27) โ€” a Chinese cybercrime group
  • Identified by: Expel researchers (July 2026) (raw/digests/Cyber-Digest-2026-07-18)
  • Confidence: Medium โ€” attribution is based on a single research report (Tier 2 source)

Modus Operandi

  • Used a modified Gh0st RAT (remote access trojan) to access a DigiCert support member's device
  • Stole code-signing certificates intended for DigiCert customers
  • The operation targeted a Certificate Authority (CA) to compromise the software supply chain downstream of the CA itself

Significance

Compromising a Certificate Authority and stealing code-signing certificates allows threat actors to sign malicious code with trusted certificates, bypassing code integrity checks. This is a supply chain attack at the trust infrastructure layer.

Related Pages

  • Digicert Breach โ€” The April 2026 security incident attributed to this group
  • Blackcat Alphv โ€” Another group with code-signing certificate theft capabilities
  • Wp Shellstorm โ€” Webshell supply chain operation