Based on our analysis, GoldenEyeDog has separate teams with dedicated resources and targets, and these separate teams can be distinguished based on code-signing certificate usage and tactics.
1/2
- In this version, CylindricalCanine still downloads the second stage from a text file hosted in the CDN. However, the files don't have normal extensions anymore. Looking in the directory shared by @elasticseclabs, we found two new certificates of interest. 🧵1/5Elastic Security Labs is tracking Golden Gh0st RAT targeting Western companies, expanding beyond its previously documented targeting of financial organizations in the Asia-Pacific region. Same TTPs as @ExpelSecurity CylindricalCanine research post: go.es.io/3TEZ0G6 The
- A self-propagating npm supply chain worm compromised keyv, cacheable, flat-cache, file-entry-cache, and 800+ downstream packages—stealing CI/CD, cloud, and API credentials along the way. (1/6)
- In April 2026, a Chinese cybercrime group accessed a support rep's device at DigiCert—then used that access to steal code-signing certificates meant for DigiCert customers. We're calling the actors CylindricalCanine. 🧵 1/4
- Researchers at @sysdig found JadePuffer used an LLM agent to conduct a ransomware attack. Is this future of ransomware? In this case, a human still steered it and struggled with the basics. okt.to/K5eTmL


