The Dragon Breath APT group has been observed deploying a sophisticated multi-stage loader known as RoningLoader to deliver a modified variant of Gh0st RAT, primarily targeting Chinese-speaking users. The campaign utilizes trojanized NSIS installers that impersonate legitimate software such as Google Chrome and Microsoft Teams, leveraging a variety of evasion techniques including the use of a legitimately signed kernel driver, custom Windows Defender Application Control (WDAC) policies, and Protected Process Light (PPL) abuse to disable Microsoft Defender and other endpoint security products. These techniques allow the attackers to bypass security controls and establish persistent remote access on compromised systems.
Elastic Security Labs researchers have detailed how the infection chain involves multiple embedded installers, with one acting as a decoy and the other initiating the attack sequence. The loader attempts to remove userland hooks by reloading ntdll.dll and uses a DLL to extract and execute shellcode from an encrypted file disguised as a PNG image. Dragon Breath, also known as APT-Q-27 and Golden Eye, has a history of targeting the online gaming and gambling industries across East Asia, and this latest campaign demonstrates their continued evolution in defense evasion and malware delivery tactics.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Security reporting described a Dragon Breath intrusion set using the RONINGLOADER malware loader to disable Windows security tools, including Windows Defender, through kernel-driver and Protected Process Light abuse. The campaign was also reported as delivering Gh0st RAT on compromised systems.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.