Skip to content
Social engineeringResolved

DigiCert support portal compromise and misissued EV code signing certificates

An attacker posing as a customer infected DigiCert support workstations via chat and harvested EV code signing initialization codes; 60 certificates were revoked, some used to sign Zhong Stealer.

Victim
DigiCert, Inc.

On 18 April 2026, DigiCert, one of the largest publicly trusted certificate authorities, opened Mozilla Bugzilla bug 2033170, titled "DigiCert: Misissued code signing certificates". The preliminary report said a malware incident had targeted a customer support team member and that the threat actor had been able to procure initialization codes for a limited number of code signing certificates, a few of which were then used to sign malware. The full incident report followed on 28 April 2026.

What happened

According to DigiCert's report, on 2 April 2026 a threat actor contacted the support team through a customer chat channel and repeatedly sent ZIP files presented as customer screenshots. The archives contained a .scr executable. Security controls blocked four delivery attempts, but a fifth compromised a support analyst's workstation. DigiCert's Trust Operations team detected and contained that machine on 3 April and judged the incident closed.

It was not. A second analyst workstation had been compromised through the same vector on 4 April, and a malfunctioning CrowdStrike deployment meant it went unnoticed. From that endpoint, the attacker used a support portal feature that lets analysts view customer accounts from the customer's perspective. That view exposed initialization codes for approved but not yet delivered EV code signing orders. As DigiCert put it, an initialization code combined with an approved order is enough to obtain the certificate, so the attacker could collect valid EV code signing certificates issued in other customers' names.

Third-party researchers began sending certificate problem reports from 5 April, which DigiCert initially treated as routine key-compromise revocations. The pattern led to a wider review, and the second compromised workstation was found on 14 April.

Impact

DigiCert revoked 60 code signing certificates between 14 and 17 April, with the revocation date backdated to each certificate's issuance date. Of these, 27 were explicitly linked to the threat actor (11 reported by community members who tied them to malware, 16 found by DigiCert) and 33 were revoked as a precaution because customer control could not be confirmed. The affected certificates came from four issuing CAs, including DigiCert Trusted G4 code signing intermediates and the reseller-branded GoGetSSL and Verokey CAs. Certificates flagged by researchers had been used to sign the Zhong Stealer malware family; press coverage citing security researchers linked the activity to a China-based crime group tracked as GoldenEyeDog (APT-Q-27).

DigiCert said it found no evidence that the attacker misused other internal systems, changed account settings, abused validation data or caused any non code signing misissuance. There was no indication that private keys held by customers were compromised.

Response

DigiCert listed four contributing factors: incomplete EDR coverage, excessive privilege in the support portal's customer view, initialization codes not being protected as bearer credentials, and permissive file transfer in support channels. Remediation included masking initialization codes and making proxied support access read-only, file-type restrictions and sandboxing for support channels, EDR policy fixes with coverage monitoring, MFA hardening and network egress controls. DigiCert reported all action items complete in July 2026, and the bug was closed on 20 July.

Why it matters

Code signing certificates, and EV ones in particular, buy malware instant credibility with operating systems and security tools. This incident shows that a CA's weakest point may not be its signing infrastructure but its help desk: a single malicious file sent through a support chat was enough to turn routine customer-service tooling into a source of trusted certificates for a malware operation.

Timeline

  1. A threat actor posing as a customer sends ZIP files disguised as screenshots through DigiCert's support chat; a fifth attempt compromises a support analyst's workstation.

  2. DigiCert's Trust Operations team detects, isolates and cleans the first compromised workstation and considers the incident contained.

  3. A second analyst workstation is compromised through the same vector; an EDR malfunction leaves it undetected.

  4. DigiCert receives the first third-party certificate problem report linking one of its code signing certificates to malware.

  5. DigiCert identifies the second compromised workstation and begins masking initialization codes in proxied support sessions.

  6. DigiCert revokes the last of 60 affected code signing certificates and cancels pending orders in the window of interest.

  7. DigiCert files a preliminary incident report on Mozilla Bugzilla (bug 2033170).

  8. DigiCert publishes its full incident report, naming the Zhong Stealer malware family.

  9. DigiCert posts its closure summary stating that all remediation action items are complete.

Sources

  1. bugzilla.mozilla.orghttps://bugzilla.mozilla.org/show_bug.cgi?id=2033170
  2. securityweek.comhttps://www.securityweek.com/digicert-revokes-certificates-after-support-portal-hack/
  3. cyberinsider.comhttps://cyberinsider.com/digicert-suffers-breach-stolen-certificates-used-to-sign-malware/

Related incidents