type: entity ยท created: 2026-07-18 ยท updated: 2026-07-18 ยท tags: [apt-group, cybercrime-group, supply-chain] ยท confidence: medium ยท affected_sectors: [technology, government] ยท au_impact: false
CylindricalCanine
CylindricalCanine is a subgroup of the Chinese cybercrime group GoldenEyeDog (APT-Q-27). The subgroup was identified by Expel researchers in July 2026 as the perpetrator of the April 2026 DigiCert security incident.
Attribution
- Parent group: GoldenEyeDog (APT-Q-27) โ a Chinese cybercrime group
- Identified by: Expel researchers (July 2026) (raw/digests/Cyber-Digest-2026-07-18)
- Confidence: Medium โ attribution is based on a single research report (Tier 2 source)
Modus Operandi
- Used a modified Gh0st RAT (remote access trojan) to access a DigiCert support member's device
- Stole code-signing certificates intended for DigiCert customers
- The operation targeted a Certificate Authority (CA) to compromise the software supply chain downstream of the CA itself
Significance
Compromising a Certificate Authority and stealing code-signing certificates allows threat actors to sign malicious code with trusted certificates, bypassing code integrity checks. This is a supply chain attack at the trust infrastructure layer.
Related Pages
- Digicert Breach โ The April 2026 security incident attributed to this group
- Blackcat Alphv โ Another group with code-signing certificate theft capabilities
- Wp Shellstorm โ Webshell supply chain operation