Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Certificate Authority (DigiCert)
Incident: Theft of customer code-signing certificates via compromise of support analyst workstations.
Impact: Attackers can sign malicious software with legitimate certificates to bypass security detections and evade trust-based filters.
Attacker: CylindricalCanine (GoldenEyeDog subgroup)
Analysis: CylindricalCanine leveraged social engineering via customer support chats to deploy a modified Gh0st RAT on employee workstations. By compromising internal support portals, the actors intercepted valid certificates meant for customers. This allows the threat group to sign malicious payloads, significantly increasing the success rate of their campaigns by mimicking trusted software.
Recommendations: Implement strict isolation and enhanced monitoring for support workstations interacting with untrusted customer uploads.; Enforce hardware-based MFA for all access to certificate issuance and management portals.; Regularly audit code-signing logs for unauthorized certificate interceptions or anomalies.
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source