DragonBreath is a financially motivated threat actor, also tracked as APT-Q-27 and Golden Eye Dog, active since at least 2020. It has targeted the online gaming and gambling sectors, including Chinese-speaking users and organizations in China, Taiwan, Hong Kong, Japan, Singapore, and the Philippines. DragonBreath distributes trojanized software installers impersonating legitimate applications and deploys a modified Gh0st RAT through its multi-stage RoningLoader framework. RoningLoader performs in-memory execution, DLL side-loading, process injection into trusted processes, privilege elevation, UAC weakening, and persistence through services and watchdog mechanisms. The group employs layered defense evasion, including terminating or disrupting endpoint-security products with a signed kernel driver, firewall manipulation, abuse of Windows application-control policy, phantom DLL side-loading, and Protected Process Light abuse against Microsoft Defender. Its Gh0st RAT variant supports host and security-product discovery, remote command execution, payload delivery, event-log clearing, process injection, keystroke logging, clipboard and active-window capture, and remotely configured clipboard hijacking. DragonBreath has also been associated with social engineering, search-engine poisoning, and DDoS activity directed at the gambling sector.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
29 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
34 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a threat actor known for using DLL sideloading, specifically a double-sideloading attack.
Conducting a stealthy malware campaign using RoningLoader to target Chinese-speaking users, disable security tools, deploy a modified gh0st RAT, and enable data theft, lateral movement, and long-term espionage.
Actor targeting primarily Chinese-speaking users using trojanized installers and a multi-stage loader (RONINGLOADER) to deploy a modified Gh0st RAT.
DragonBreath is referenced in connection with RONINGLOADER and a technique described as a new path to PPL abuse.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.