GoldenEyeDog, a Chinese cybercrime group linked to the Golden Gh0st malware family, is back in focus after an intrusion at DigiCert exposed the risks around code-signing certificates. The attackers used the access to intercept customer certificate activation codes and sign their own malicious files. The operation relied on a simple but effective route into a sensitive environment. Malicious files were disguised as screenshots, delivered through phishing emails or support-ticket submissions, and opened by staff who believed they were reviewing customer content. Expel said in a report shared with Cyber Security News (CSN) that the activity was carried out by a GoldenEyeDog subgroup it calls CylindricalCanine. Researchers...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!