Protect.Computer
NEWS

Hackers Breached DigiCert and Stole Code-Signing Certificates

· 1 min read · Malicious byte Got hacked
Hackers Breached DigiCert and Stole Code-Signing Certificates

In April 2026, a subgroup of the Chinese cybercrime organization GoldenEyeDog — tracked by researchers as “CylindricalCanine” — broke into DigiCert’s internal support system. DigiCert is one of the world’s largest providers of digital certificates, the electronic “seals of approval” that tell your computer a piece of software is from a trusted publisher.

The attackers tricked a DigiCert support employee into opening a malicious file disguised as a screenshot, then used the compromised account to view customer portals and steal code-signing certificates. Code-signing certificates are what allow your operating system to display “Verified publisher: Company Name” when you install software. With a stolen certificate, attackers can disguise malware as legitimate software. DigiCert discovered the breach, revoked all identified stolen certificates within 24 hours, and set the revocation date to their original issuance date so systems would immediately treat them as invalid.

How to check if you’re affected

Affected products are any software installers you download from outside official app stores, particularly in the period from April to July 2026. To stay safe:

  • Only install software from official websites or trusted app stores (Microsoft Store, Apple App Store, Google Play). Attackers who obtained stolen certificates would likely distribute malware via unofficial channels.
  • Check the publisher name when Windows shows a User Account Control (UAC) prompt during installation. If the publisher name seems unfamiliar for the software you are installing, cancel and verify the source.
  • Keep your operating system updated — modern Windows and macOS regularly refresh their certificate revocation lists, which now flag the stolen DigiCert certificates as invalid.

Sources

Related reading