75 stolen signatures of DigiCert and Trojans of 2008. Hackers have found a new way to bypass Windows protection

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
345
Reaction score
508
Deposit
0$
Cybercriminals found a way to turn Windows’s trust in digital signatures into a weapon and used an infected computer of an employee DigiCert to intercept the company’s customer certificates. Behind the attack was the Chinese band GoldenEye Dog, which then signed with stolen certificates its own malware.

The attackers entered the system in April 2026. They sent a DigicCert file disguised as a screenshot. The application got into the internal processing system of appeals, after which the employee downloaded and launched an attachment. The malware gained access to his computer and stole activation codes intended for customers who extended the certificates for the signature of the programs.

Such certificates help Windows determine the origin of the application. GoldenEyeDog used them to make malicious files less likely to cause warnings from the SmartScreen security filter. Since 2024, experts have recorded at least 75 certificates with which the group signed their bootloaders.

The main tool of the criminals was the Golden Gh0st RAT program, created on the basis of the Gh0st RAT Trojan, the source code of which appeared in the public domain back in 2008. The new version allows you to remotely control the infected computer, take screenshots, record keystrokes, run commands, upload files and delete traces of work.
The Trojan also steals data from Chrome, Firefox, Skype, Tencent browsers and 360, completes their processes and copies profile files. In addition, the program is able to clean Windows logs, delete directories, restart your computer and create a hidden administrator account for constant access via a remote desktop.

Before launching the Trojan, the Golden Gh0st Loader bootloader is used. It downloads a regular signed program, a malicious library and an encrypted file with the main load. The adhesive application launches a swapped library that deciphers the Trojan right in memory. This scheme helps to hide the malicious code from part of the protective means.

The infrastructure and methods of GoldenEyeDog have changed little. Criminals still send files under the guise of images, send emails to support services and store the following stages of infection in cloud storage. The goals of the group are often the financial institutions of the Asia-Pacific region.

Golden Gh0st RAT exchanges commands with control servers via WebSocket connection. The transmitted data is encrypted with built-in keys, the same in several versions of the Trojan. Expel specialists were able to extract the keys, decrypt the network exchange and monitor the operation of the malware in an isolated corporate environment.

During the observation, the Trojan transmitted to operators information about the infected computer, file lists and screenshots, and later received an additional module for fixing in the system. Experts also prepared rules for detecting characteristic network traffic and published a list of 1926 related files.
 
Top Bottom