GoldenEyeDog is a Chinese cybercrime threat actor, also tracked as APT-Q-27, Dragon Breath, and Miuuti Group. The group has been active since at least 2015 and is associated with financially motivated intrusions, malware distribution, and abuse of trusted software-signing mechanisms. It is known for targeting gambling and gaming organizations and has also been linked to campaigns affecting finance and Web3-related entities, particularly in the Asia-Pacific region. GoldenEyeDog is closely associated with the Golden Gh0st malware family, including Golden Gh0st Loader and Golden Gh0st RAT, and has also been linked in reporting to activity involving Zhong Stealer. Its operations commonly rely on social engineering and phishing lures, especially files disguised as screenshots or business documents, as well as counterfeit websites that impersonate legitimate software or services to deliver malware. A recurring delivery pattern uses DLL sideloading with legitimate executables, encrypted staged payloads, and decoy content to reduce suspicion. Golden Gh0st RAT, used by GoldenEyeDog and at times attributed to a subgroup tracked as CylindricalCanine, is a modular remote access trojan derived from Gh0st RAT. Observed capabilities include remote command execution, credential theft, screenshot capture, keylogging, process enumeration, payload delivery, SOCKS proxying, persistence, and anti-forensic actions such as clearing event logs or removing traces of activity. Some observed plugins have enabled remote desktop access and established privileged backdoor accounts. Command-and-control communications have been described as using WebSocket-based transport with encrypted payload content. A notable 2026 operation linked to a GoldenEyeDog subgroup involved compromise of a certificate authority support environment through a malicious file submitted via a customer support workflow. The intrusion enabled theft of certificate activation information and fraudulent acquisition of code-signing certificates, which were then used to sign malware. This activity underscored the group’s operational emphasis on abusing valid code-signing certificates to improve trust and evade security controls such as reputation-based defenses. GoldenEyeDog has also been referenced in connection with broader Silver Fox and Winos ecosystem activity, reflecting overlap in tooling, malware reuse, or shared tradecraft across Chinese cybercrime operations. However, the strongest high-confidence association remains the group’s use of Golden Gh0st malware, phishing and fake software lures, DLL sideloading, and certificate abuse in financially motivated campaigns. Known subgroup reporting includes CylindricalCanine.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
51 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
74 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese cybercrime group tied to the Golden Gh0st malware family and implicated in the DigiCert intrusion, where attackers used phishing emails and support-ticket submissions with disguised malicious files to gain access, intercept certificate activation codes, and sign malware with stolen code-signing certificates.
Chinese cybercrime group described as the parent group of CylindricalCanine. Known for targeting gambling and gaming sectors and using counterfeit websites to distribute malware-laced software; also linked here to malware-enabled access against DigiCert.
Chinese cybercrime group active since at least 2015, regularly updating malware and tactics, using code-signing certificates to bypass Windows SmartScreen, and associated with Golden Gh0st Loader and Golden Gh0st RAT. The group was tied to the April 2026 DigiCert intrusion used to steal customer certificate initialization codes and sign malware.
Linked to campaigns distributing Zhong Stealer, including use of stolen EV code-signing certificates to sign payloads and support malware delivery aimed at evading endpoint detection; attribution for the DigiCert breach itself is explicitly unconfirmed.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.