Dragon Breath is a financially motivated Chinese-nexus threat actor tracked as APT-Q-27 and also associated with the alias Golden Eye Dog. The group has been active since at least 2020 and is best known for targeting the online gaming and gambling sectors, as well as Chinese-speaking users and organizations across East and Southeast Asia, including victims in China, Taiwan, Hong Kong, Japan, Singapore, and the Philippines. Dragon Breath commonly relies on social engineering and search-engine poisoning to distribute trojanized software installers masquerading as legitimate applications. Recent activity has featured a multi-stage loader known as RoningLoader, delivered through MSI and NSIS-based installer chains, to deploy an updated variant of Gh0st RAT. The actor has demonstrated a strong emphasis on defense evasion and operational resilience, using layered techniques such as DLL side-loading, in-memory shellcode execution, thread-pool-based process injection, service-based persistence, watchdog mechanisms, privilege escalation, and abuse of Protected Process Light to interfere with Microsoft Defender. The group has also used a legitimately signed kernel driver to terminate security processes and has deployed an unsigned Windows Defender Application Control policy to block or disrupt Chinese security products, including software from Qihoo 360 and Huorong. Additional observed behavior includes disabling User Account Control, modifying firewall settings, enumerating and killing endpoint protection processes, and injecting into trusted high-privilege processes to conceal execution. Dragon Breath’s final-stage malware is a modified Gh0st RAT that provides broad remote-access functionality, including command execution, file transfer and execution, process injection, host reconnaissance, keylogging, clipboard theft and hijacking, and active-window logging. Reporting has also linked the group to social engineering, distributed denial-of-service activity, and broader intrusion operations aligned with financially motivated objectives. Dragon Breath is notable for combining commodity malware lineage with increasingly sophisticated loader engineering and anti-defense tradecraft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
29 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
34 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a threat actor known for using DLL sideloading, specifically a double-sideloading attack.
Conducting a stealthy malware campaign using RoningLoader to target Chinese-speaking users, disable security tools, deploy a modified gh0st RAT, and enable data theft, lateral movement, and long-term espionage.
Actor targeting primarily Chinese-speaking users using trojanized installers and a multi-stage loader (RONINGLOADER) to deploy a modified Gh0st RAT.
DragonBreath is referenced in connection with RONINGLOADER and a technique described as a new path to PPL abuse.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.