GoldenEyeDog is a Chinese cybercrime group active since at least 2015 and also tracked as APT-Q-27, Dragon Breath, and Miuuti Group. The cluster appears to include multiple subgroups, notably CylindricalCanine and CuboidalCanine, which share broader tradecraft but operate with partially distinct malware sets and code-signing certificate inventories. GoldenEyeDog has been linked to the Golden Gh0st malware family and to activity involving ValleyRAT, also known as WinOS or SilverFox, although attribution of ValleyRAT operations relies on the surrounding delivery chain, lures, and certificate abuse rather than the malware family alone because that tooling is publicly available. The actor is known for malware delivery through phishing and counterfeit or watering-hole websites. Reported lures include files disguised as screenshots and fake software download pages. GoldenEyeDog commonly uses DLL sideloading, encrypted payload staging, decoy documents, and extensive abuse of valid code-signing certificates to improve trust and evade security controls. Certificate abuse has been a core element of its operations since at least 2017, and more recent activity shows sustained operational reliance on stolen or fraudulently obtained code-signing certificates. CylindricalCanine, a subgroup associated with Golden Gh0st Loader and Golden Gh0st RAT, has targeted corporations including finance organizations in the Asia-Pacific region. Its malware supports remote access, credential theft, keylogging, screenshot capture, process enumeration, shell command execution, payload delivery, proxying, persistence, and anti-forensic actions such as log clearing. Observed post-compromise behavior also includes creation of privileged backdoor accounts and enabling remote desktop access. CuboidalCanine, another subgroup linked to GoldenEyeDog, has been associated with ValleyRAT campaigns targeting the gambling industry through watering-hole operations. GoldenEyeDog has been associated with targeting gambling and gaming ecosystems in Southeast Asia and broader Asia-Pacific organizations, with some reporting also tying its operations to Web3-related victims. In 2026, a subgroup assessed as CylindricalCanine was linked to the compromise of DigiCert support workstations through malicious files submitted via support channels. The intrusion enabled theft of certificate initialization data and interception of code-signing certificates intended for customers, which were then used to sign the group’s malware. That incident highlighted the actor’s mature operational focus on certificate abuse as both an evasion mechanism and an enabler for malware deployment. The group’s infrastructure and malware development patterns indicate a modular, tool-based approach. GoldenEyeDog’s subgroups appear to keep most malware and certificate usage separate, but limited overlap in certificate usage suggests either a shared internal supply chain or access to a common certificate source. Overlaps between certificates tied to GoldenEyeDog activity and other criminal malware ecosystems suggest interaction with a broader underground market for code-signing assets. The actor’s overall profile is that of a Chinese e-crime operation focused on credential theft, remote access, persistence, and stealthy malware delivery against gambling, gaming, financial, and corporate targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
51 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
84 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Chinese cybercrime group with multiple subgroups. It has historically targeted individuals and organizations involved in gambling in Southeast Asia, while one subgroup also targets corporations. The group is associated with Gh0st RAT variants, ValleyRAT, watering hole delivery, phishing attachments, DLL side-loading, and extensive abuse of code-signing certificates.
Chinese cybercrime group tied to the Golden Gh0st malware family and implicated in the DigiCert intrusion, where attackers used phishing emails and support-ticket submissions with disguised malicious files to gain access, intercept certificate activation codes, and sign malware with stolen code-signing certificates.
Chinese cybercrime group described as the parent group of CylindricalCanine. Known for targeting gambling and gaming sectors and using counterfeit websites to distribute malware-laced software; also linked here to malware-enabled access against DigiCert.
Chinese cybercrime group active since at least 2015, regularly updating malware and tactics, using code-signing certificates to bypass Windows SmartScreen, and associated with Golden Gh0st Loader and Golden Gh0st RAT. The group was tied to the April 2026 DigiCert intrusion used to steal customer certificate initialization codes and sign malware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.