Golden Gh0st RAT: Inside the DigiCert Certificate Theft

Golden Gh0st RAT malware abusing stolen DigiCert code-signing certificates to bypass Windows SmartScreen

Cybercriminals have found a way to weaponise Windows’ faith in digital signatures. They compromised the workstation of a DigiCert employee and intercepted certificates bound for the company’s customers. A Chinese cybercrime group stood behind the operation. Afterwards, they signed their own malware with the stolen credentials.

Expel researchers have named the responsible subgroup CylindricalCanine, tracked internally as Expel-TA-0002. The team places it within the larger GoldenEyeDog cluster, which Qi’anxin follows as APT-Q-27. Notably, Expel itself spotted the anomalous certificate activity and alerted DigiCert, which then investigated and published a detailed incident report.

How the Intrusion Unfolded

The attackers slipped into the system in April 2026. They submitted a file to DigiCert support disguised as a screenshot. The ticket landed in the internal handling system, whereupon an employee downloaded and executed the attachment. The malware promptly seized control of the machine.

From there, the operators harvested initialisation codes destined for customers renewing their code-signing certificates. Those codes carry real weight: they let a customer activate the physical hardware token used for signing. Consequently, the theft handed the group a legitimate signing capability rather than mere data.

Why Certificates Are the Prize

Such certificates help Windows establish an application’s provenance. CylindricalCanine wielded them so that malicious files would trip SmartScreen warnings less often. Microsoft has tightened this ground, however. Extended Validation certificates once suppressed SmartScreen outright; now certificates receive less automatic trust, and files must earn reputation over time.

The scale is considerable. Since 2024, the Cert Graveyard project has catalogued 75 unique code-signing certificates used to sign Golden Gh0st Loader.

Golden Gh0st RAT: An Old Trojan Reborn

The group’s principal instrument is Golden Gh0st RAT. It descends from Gh0st RAT, whose source code entered the public domain back in 2008. Analysts previously catalogued parts of this family as Zhong Stealer. Expel’s analysis, however, shows the malware functions chiefly as a remote access trojan rather than a simple credential thief.

The current build grants remote control of an infected machine. It captures screenshots, logs keystrokes, executes commands, downloads files, and erases its own traces.

Credential Harvesting and Anti-Forensics

The trojan also plunders data from Chrome, Firefox, and Skype. Tencent’s QQ Browser and both 360 browsers likewise fall within its reach. It terminates their processes first, then copies the profile files.

Its destructive repertoire runs deeper still. The malware wipes the Application, Security, and System event logs. Furthermore, it deletes directories recursively, reboots the host, and can even destroy itself on command.

The Loader and the Sideloading Chain

Golden Gh0st Loader precedes the trojan. It retrieves three components: a legitimate signed application, a malicious library, and an encrypted payload file. The benign executable then loads the substituted library through DLL sideloading. That library decrypts the trojan directly in memory. Accordingly, the scheme conceals the malicious code from a portion of defensive tooling.

GoldenEyeDog’s infrastructure and methods have shifted remarkably little. The operators still distribute files masquerading as images. They still route emails into support desks. Moreover, they continue to stage later infection phases in cloud storage. Financial organisations across the Asia-Pacific region remain their favoured targets.

Decrypting the Command Channel

Golden Gh0st RAT exchanges commands with its servers over plain WebSocket traffic, without TLS. Observed connections favour low-numbered ports, chiefly 5188 and 5198. The payloads themselves rely on hardcoded keys that recur across several versions of the trojan.

That reuse proved costly for the operators. Expel specialists extracted the keys, decrypted the network exchange, and observed the malware at work inside an isolated enterprise environment.

What the Researchers Watched

During their observation, the trojan relayed host fingerprints, file listings, and screenshots to the operators. Days later, it received an additional module for persistence. That plugin creates a hidden administrator account using credentials baked into the payload. It then edits the Winlogon registry key to permit automatic logon and suppress credential prompts, opening an RDP backdoor.

Detection Opportunities

The custom protocol offers defenders a foothold. Expel built Suricata rules in collaboration with Proofpoint, and those signatures now ship in the ETPro and ETOpen rulesets. The researchers additionally published a list of 1,926 associated files. Worth noting, though: those signed files are not exclusive to CylindricalCanine.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply