CYBER DESK · HONG KONG · WEEKLY

DigiCert's Breach Has Two Different Owners

Expel's attribution of the DigiCert certificate breach to a Chinese state-linked group rests on a malware signature, not DigiCert's own forensics, and this week's wire coverage flattened Expel's 'linked to' language into 'confirmed.'
KT

Confirmed Mechanism Inferred Actor

DigiCert's own account of April 2, 2026 is precise: a support agent opened a ZIP file that arrived through the chat widget disguised as a customer screenshot, and inside was a .scr screensaver executable that compromised two internal systems. One was caught within 24 hours. The other sat undetected for roughly two weeks. That's DigiCert's own forensics, confirmed and timestamped, and it's the reason 60 EV Code Signing certificates across four Certificate Authorities got revoked between April 14 and 17, with 27 of those tied directly to attacker activity.

What DigiCert has not said is who did it. That claim arrived July 17, from Expel researcher Aaron Walton, linking the operation to CylindricalCanine, a subgroup of the Chinese-nexus GoldenEyeDog cluster (also tracked as APT-Q-27 or Dragon Breath) active since roughly 2015. The link is real. It is also downstream: the stolen certificates were used to sign Zhong Stealer payloads, and Zhong Stealer is the malware family Expel associates with GoldenEyeDog. Risky Business Media's own reporting says the quiet part out loud, that 'it's unclear if they're the ones who hacked DigiCert.' A signing habit is not a fingerprint at the door.

Same Headline Different Evidence

Compare that confidence gap to Elastic Security Labs' July 18 disclosure of REF9403, a DPRK-aligned campaign called Contagious Interview that hides a four-stage OtterCookie-aligned payload inside SVG image files, specifically the comment blocks of fake flag icons bundled into trojanized coding-test repositories sent to job applicants. Zero antivirus engines flagged the malicious repos at the time Elastic published. Here the forensic chain runs the opposite direction from DigiCert: the payload mechanics are documented stage by stage, and the DPRK attribution sits on technique overlap the industry has stress-tested across multiple incident reports since Contagious Interview was first named. Nobody needed Risky Business to hedge on that one.

Walton's research reads as careful and says so itself; the gap is not in his methodology but in what happens to it downstream. A headline built on primary forensics and one built on a signing pattern produce an identical sentence. A certificate breach attributed to a named cluster reads the same in an inbox digest whether the vendor confirmed the actor or a malware family did it for them, and the CISO scanning that digest at 8am has no way to tell which sentence rests on DigiCert's confirmed forensics and which rests on Expel's inference from a signing pattern.

DigiCert has not disputed the GoldenEyeDog attribution, but it has not endorsed it either. That silence means the certificate-authority-compromise attribution is running on Expel's malware analysis alone, with no forensic confirmation from the breached party. What matters more than the identity question is the industry's growing tolerance for treating 'linked to' as a synonym for 'confirmed.' If Expel is right, this is CylindricalCanine's first documented certificate-authority compromise. If it's wrong, the actual intruder's signing capability is still unaccounted for, and no wire report has flagged that gap.

Sources

PREVIOUS COLUMNS, CYBER INTEL DESK
The Wang Report's columns are produced by AI under human editorial oversight. See our Editorial Standards.