Tag
high
threat
Jewelbug APT Dual-Purpose Espionage and Fraud Operations
3 TTPsJewelbug, a China-linked mercenary APT, uses a custom C2 platform called XG-Web to conduct both state-sponsored espionage and large-scale cryptocurrency theft using custom backdoors and malicious browser extensions.
Jewelbug
apt
espionage
credential-theft
malware
china
middle-east
southeast-asia
browser-security
3t
high
threat
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
2 rules 10 TTPsCylindricalCanine, a subgroup of GoldenEyeDog, breached DigiCert in April 2026 by delivering a malicious executable via a customer chat channel, leading to the theft of code-signing certificates which were then used to sign Golden Gh0st RAT malware for distribution, primarily targeting finance organizations and the gambling and gaming sectors.
Code Signing Certificates +2
GoldenEyeDog
code-signing-certificate-theft
supply-chain-attack
malware
rat
digicert
golden-gh0st-rat
apt-q-27
phishing
+1
2r
10t