RONINGLOADER is a multi-stage Windows loader used by the financially motivated DragonBreath threat group, also tracked as APT-Q-27 and GoldenEyeDog. It has been distributed in trojanized MSI and NSIS installers impersonating legitimate software, principally against Chinese-speaking users and entities associated with online gaming and gambling. The loader decrypts and executes subsequent stages in memory, then deploys a modified Gh0st RAT payload.
RONINGLOADER performs extensive endpoint-security evasion. It enumerates security products; attempts elevation and disables UAC; manipulates firewall rules; uses a signed kernel driver to terminate security processes; employs phantom DLL side-loading; and injects shellcode into legitimate Windows processes, including high-privilege processes. It also abuses Protected Process Light functionality to corrupt Microsoft Defender components and deploys an unsigned Windows Defender Application Control policy targeting selected Chinese security products. Persistence mechanisms include malicious services and watchdog logic that restarts malicious execution when an injected target process exits.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Elastic Security Labs identified a campaign using a unique loader named RoningLoader, delivered through trojanized NSIS installers and followed by extensive endpoint-security evasion and payload injection.
Elastic Security Labs identified a campaign using a unique loader named RoningLoader, delivered through trojanized NSIS installers and followed by extensive endpoint-security evasion and payload injection.
Elastic Security Labs detailed the adversary's use of a multi-stage loader codenamed RONINGLOADER to distribute a Gh0st RAT variant through NSIS installers masquerading as legitimate programs like Google Chrome and Microsoft Teams.
Through this report, we hope to raise awareness of new techniques this malware is starting to implement and to shine a light on a unique loader we are naming RoningLoader.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware injects shellcode into vssvc.exe and svchost.exe through Windows thread-pool tasks, and injects subsequent payloads into TrustedInstaller.exe or elevation_service.exe with VirtualAllocEx, WriteProcessMemory, and CreateRemoteThread.
The malware then injects code into regsvr32.exe — a native Windows utility — using CreateRemoteThread and LoadLibrary (T1055.001), pushing execution into high-privilege processes like TrustedInstaller.exe to conceal its activity further.
It grants itself the high integrity SeDebugPrivilege token before injecting into vssvc.exe.
RONINGLOADER to distribute a Gh0st RAT variant through NSIS installers masquerading as legitimate programs like Google Chrome and Microsoft Teams.
Trojanized NSIS installers masquerade as legitimate software such as Google Chrome and Microsoft Teams.
The malware injects shellcode into vssvc.exe and svchost.exe through Windows thread-pool tasks, and injects subsequent payloads into TrustedInstaller.exe or elevation_service.exe with VirtualAllocEx, WriteProcessMemory, and CreateRemoteThread.
The malware then injects code into regsvr32.exe — a native Windows utility — using CreateRemoteThread and LoadLibrary (T1055.001), pushing execution into high-privilege processes like TrustedInstaller.exe to conceal its activity further.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-stage loader used to distribute a Gh0st RAT variant via trojanized NSIS installers masquerading as legitimate software.
A multi-stage malware loader delivered via trojanized NSIS installers. It uses DLL side-loading, in-memory shellcode execution, code injection, privilege escalation, UAC disabling, and a signed kernel driver to disable security tools before deploying a final payload.
Multi-stage loader used to disable security tools and deliver a modified Gh0st RAT payload.
A loader associated with the DragonBreath actor, discussed in the context of abusing PPL (Protected Process Light) mechanisms.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.