DigiCert disclosed a breach in which a threat actor socially engineered its support team with a malicious ZIP file disguised as a customer screenshot, compromising two analyst workstations and gaining access to initialization codes for previously approved but undelivered EV code-signing certificate orders. The attacker used that access to obtain legitimate trusted code-signing certificates, and DigiCert revoked 60 certificates in response, including 27 directly linked to the intrusion. Reporting indicates 11 of those certificates were already used in the wild to sign Zhong Stealer malware, while a misconfigured CrowdStrike EDR agent on one compromised machine helped the attacker remain undetected for nearly two weeks.
The incident unfolded alongside a separate trust-related disruption affecting DigiCert certificates on Windows systems: a faulty Microsoft Defender signature update released around April 30 falsely detected the legitimate DigiCert Assured ID Root CA and DigiCert Trusted Root G4 certificates as Trojan:Win32/Cerdigent.A!dha. On affected hosts, Defender quarantined registry entries from the Windows trust store, raising the risk of SSL/TLS validation failures, broken code-signing verification, browser warnings, and enterprise application outages. Microsoft acknowledged the false positives and issued corrected definitions, with version .430 cited as restoring the removed certificates automatically, while DigiCert tightened controls by enforcing MFA on administrative workflows, restricting access to initialization codes, limiting attachment types in support channels, and improving logging.

Pull IOCs and campaign context straight into your stack.
12 events from the most recent confirmed update back to the earliest known activity.
Researchers said the April 2026 DigiCert intrusion was carried out by a threat cluster they track as CylindricalCanine, which Expel assesses is a subgroup of the Chinese cybercrime group GoldenEyeDog. This extends prior reporting by attributing the DigiCert support-environment breach itself, not just the Zhong Stealer malware signed with abused certificates.
Expel released a technical report on CylindricalCanine describing Golden Gh0st Loader and Golden Gh0st RAT, including decrypted protocol behavior, tooling to recover victim telemetry, and the malware’s broader capabilities. The report also published infrastructure, hashes, protocol details, and Suricata detections to help defenders identify the activity.
Researchers associated the Zhong Stealer malware signed with abused DigiCert-issued certificates with the threat group GoldenEyeDog (APT-Q-27). DigiCert did not confirm that this group was responsible for the breach of its support environment itself.
In response to the April intrusion, DigiCert enforced MFA on administrative workflows, restricted access to initialization codes during proxied customer sessions, limited attachment file types in support channels, and improved logging. These measures were introduced to reduce the risk of similar certificate issuance abuse.
Microsoft acknowledged the Defender detection problem and released corrective security intelligence updates. Definition version .430 was cited as a key fix that began automatically restoring the quarantined DigiCert certificates on affected systems.
Security researcher Florian Roth publicly drew attention to the Microsoft Defender false-positive issue and shared ways for administrators to verify whether the affected DigiCert root certificates had been restored. His reporting helped clarify the operational impact on Windows trust stores.
Around April 30, 2026, a Microsoft Defender antimalware signature update began falsely detecting the legitimate DigiCert Assured ID Root CA and DigiCert Trusted Root G4 certificates as Trojan:Win32/Cerdigent.A!dha. On affected Windows systems, Defender quarantined related registry entries from the Windows trust store, risking SSL/TLS validation and code-signing failures.
As part of its response to the support-system intrusion, DigiCert cancelled pending EV code-signing certificate orders associated with the exposed initialization-code workflow. The step was taken to cut off any further certificate issuance opportunities tied to the compromised support access.
Following its investigation, DigiCert revoked 60 code-signing certificates, including 27 linked directly to the attacker. The revocations were intended to contain abuse of trusted certificates obtained during the intrusion.
One compromised DigiCert machine had a misconfigured CrowdStrike EDR agent, which allowed the attacker to remain undetected for nearly two weeks. This prolonged the impact of the intrusion and delayed response.
After compromising DigiCert support systems, the attacker obtained legitimate EV code-signing certificates tied to previously approved orders. DigiCert later determined that 27 revoked certificates were directly associated with the attacker, and 11 had already been used to sign Zhong Stealer malware in the wild.
In early April 2026, a threat actor socially engineered DigiCert support staff by sending a ZIP file disguised as a customer screenshot through a chat channel. Two support analyst machines were compromised, giving the attacker access to initialization codes for previously approved but undelivered EV code-signing certificate orders.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 29 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
8 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcethehackernews.com
Open sourceexpel.com
Open sourcecybersecuritynews.com
Open sourcedarkwebinformer.com
Open sourcecybersecuritynews.com
Open sourceopennet.me
Open sourcebugzilla.mozilla.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.