On August 18, we caught a malware loader we believe to be novel. Entry point: a threat actor phished a client’s user through Microsoft Teams, posing as the IT help desk. We named it SynkLoader. (1/7)
Based on our analysis, GoldenEyeDog has separate teams with dedicated resources and targets, and these separate teams can be distinguished based on code-signing certificate usage and tactics.
1/2
In this version, CylindricalCanine still downloads the second stage from a text file hosted in the CDN. However, the files don't have normal extensions anymore.
Looking in the directory shared by @elasticseclabs, we found two new certificates of interest.
🧵1/5
Elastic Security Labs is tracking Golden Gh0st RAT targeting Western companies, expanding beyond its previously documented targeting of financial organizations in the Asia-Pacific region.
Same TTPs as @ExpelSecurity CylindricalCanine research post: go.es.io/3TEZ0G6
The
A self-propagating npm supply chain worm compromised keyv, cacheable, flat-cache, file-entry-cache, and 800+ downstream packages—stealing CI/CD, cloud, and API credentials along the way. (1/6)
In April 2026, a Chinese cybercrime group accessed a support rep's device at DigiCert—then used that access to steal code-signing certificates meant for DigiCert customers. We're calling the actors CylindricalCanine. 🧵 1/4