GoldenEyeDog is a Chinese cybercrime group active since at least 2015. It is also tracked as APT-Q-27, Dragon Breath, and Miuuti Group. The group has targeted gambling and gaming entities, as well as finance organizations in the Asia-Pacific region, using counterfeit software-download sites, watering-hole activity, and phishing lures masquerading as screenshots or other benign files. GoldenEyeDog includes at least two tracked subgroups: CylindricalCanine (Expel-TA-0002) and CuboidalCanine (Expel-TA-0003). CylindricalCanine uses Golden Gh0st Loader and Golden Gh0st RAT, a modified Gh0st RAT variant, principally against corporate targets. It delivers payloads through phishing and support-channel submissions, commonly uses DLL sideloading, encrypted staged payloads, decoy documents, and legitimate or fraudulently obtained code-signing certificates to reduce security-control scrutiny. Golden Gh0st RAT supports remote command execution, browser-credential collection, keylogging, screenshot capture, process enumeration, SOCKS proxying, payload delivery, persistence, and log clearing; an observed plugin also created an administrator-level backdoor account and enabled remote desktop access. CuboidalCanine has been linked to ValleyRAT activity targeting the gambling industry, including watering-hole delivery. ValleyRAT attribution requires contextual analysis because the malware has been publicly distributed and used by multiple actors. GoldenEyeDog has relied extensively on code-signing certificate abuse since at least 2017, with the two subgroups generally maintaining distinct certificate inventories but showing limited overlap consistent with a common certificate supply source. The group has also been associated with signed malware used to bypass Windows security protections.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
49 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
84 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A threat actor associated in the content with use of ValleyRAT. Its CuboidalCanine subgroup is assessed to have transitioned away from Gh0st RAT and targets gambling organizations.
A Chinese cybercrime group with multiple subgroups. It has historically targeted individuals and organizations involved in gambling in Southeast Asia, while one subgroup also targets corporations. The group is associated with Gh0st RAT variants, ValleyRAT, watering hole delivery, phishing attachments, DLL side-loading, and extensive abuse of code-signing certificates.
Chinese cybercrime group tied to the Golden Gh0st malware family and implicated in the DigiCert intrusion, where attackers used phishing emails and support-ticket submissions with disguised malicious files to gain access, intercept certificate activation codes, and sign malware with stolen code-signing certificates.
Chinese cybercrime group described as the parent group of CylindricalCanine. Known for targeting gambling and gaming sectors and using counterfeit websites to distribute malware-laced software; also linked here to malware-enabled access against DigiCert.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.