← Back to blog

GoldenEyeDog Subgroup Tied to DigiCert Breach and Stolen Certificates

A new subgroup linked to the GoldenEyeDog threat actor was responsible for breaching DigiCert and stealing code-signing certificates. The breach highlights risks to software supply chains and certificate authorities.

TL;DR

  • CylindricalCanine, a subgroup of GoldenEyeDog, breached DigiCert in April 2026.
  • Attackers stole code-signing certificates used to verify software authenticity.
  • The group is known for targeting gaming and gambling sectors.
  • Certificate theft poses serious risks to software trust and supply chain integrity.
  • Organizations should audit certificate usage and monitor for misuse.

In a significant security incident, cybersecurity researchers have traced the April 2026 DigiCert breach to a threat actor subgroup called CylindricalCanine. This group, part of the larger GoldenEyeDog cybercrime collective, targeted DigiCert to steal code-signing certificates—critical tools that help verify legitimate software.

The breach underscores ongoing threats to certificate authorities and the broader software supply chain. Code-signing certificates, when compromised, can allow attackers to distribute malware that appears trustworthy, making detection harder and impact more severe. Organizations relying on digital certificates must now reassess their exposure and strengthen monitoring practices.

Who Is CylindricalCanine?

  • CylindricalCanine is a newly identified subgroup within the GoldenEyeDog threat actor cluster.
  • GoldenEyeDog, also known as APT-Q-27 or Dragon Breath, has primarily targeted online gaming and gambling platforms.
  • This group is believed to operate from China and has shown increasing sophistication in breaching high-value targets.
  • Prior campaigns involved credential theft, network infiltration, and lateral movement tactics.

Impact of the DigiCert Breach

  • DigiCert confirmed unauthorized access leading to theft of code-signing certificates in April 2026.
  • Stolen certificates could be used to sign malicious software, bypassing security controls.
  • Organizations using DigiCert-issued certificates should evaluate revocation and reissuance strategies.
  • The breach raises concerns over trust in centralized certificate authorities and highlights the need for robust key management practices.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

GoldenEyeDog Subgroup Tied to DigiCert Breach and Stolen Certificates — Agent Breach Blog | Agent Breach