DigiCert, one of the world’s leading Certificate Authorities (CAs), has confirmed a serious cybersecurity incident in April 2026 that resulted in the theft of 60 Extended Validation (EV) code signing certificates.
These certificates are highly trusted and are typically used by software vendors to prove that their applications are legitimate and safe.
Attackers abused these stolen certificates to sign malicious files, specifically the “Zhong Stealer” malware.
Because the malware appeared to be signed by trusted companies, it was able to bypass security warnings and appear legitimate to users and security systems.
Initial Attack Vector: Weaponized Screensaver File
The breach began with a social engineering campaign targeting DigiCert’s customer support team.
The attacker used a Salesforce chat channel to send multiple messages posing as a customer seeking help.
Attached to these messages was a ZIP file disguised as a harmless screenshot. Inside the archive was a malicious .scr file, which is a Windows screensaver executable.
This file contained hidden malware designed to compromise the system once opened.
DigiCert’s defenses initially blocked four attempts. However, the fifth attempt succeeded after a support analyst executed the file.
After gaining access to the compromised machine, the attacker moved laterally into DigiCert’s internal support systems.
They accessed a support portal tool that allows staff to view customer accounts for troubleshooting.
Although this tool had restrictions, such as preventing password changes or new certificate orders, it still exposed sensitive data.
Specifically, it revealed initialization codes tied to EV code signing certificates that had been approved but not yet issued.
Using these codes, the attackers were able to generate valid certificates across multiple accounts fraudulently.
DigiCert later confirmed that 60 certificates were issued across four different Certificate Authorities.
The stolen certificates were issued under the names of well-known technology companies, including Lenovo, Kingston, Shuttle Inc., and Palit Microsystems. This made the signed malware appear highly trustworthy.
At least 27 of the certificates were directly linked to malicious activity. Security researchers observed that these certificates were used to sign Zhong Stealer malware, allowing it to evade detection tools and security prompts.
Due to the high risk, DigiCert treated all 60 certificates as fully compromised, regardless of confirmed usage.
DigiCert identified the breach by mid-April 2026 and acted quickly. Within 24 hours, the company revoked all 60 compromised certificates.
It also canceled any pending certificate orders that may have been exposed during the attack window.
To prevent similar incidents, DigiCert implemented several security improvements:
- Removed visibility of initialization codes from support tools at both UI and API levels
- Suspended affected support accounts
- Disabled Okta FastPass access for the support portal
- Enforced stricter multi-factor authentication (MFA) controls
This incident highlights how trusted infrastructure like certificate authorities can become high-value targets.
Even a single compromised endpoint, combined with social engineering and visibility into internal systems, can lead to large-scale abuse.
It also shows the risks of signed malware. When attackers use legitimate certificates, traditional security controls may fail to detect threats, making such attacks especially dangerous for enterprises and end users alike.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google