Sophos reported that Operation Dragon Breath—also tracked as APT-Q-27 and Golden Eye Dog—is using an expanded DLL sideloading chain to infect Windows users through trojanized installers posing as Telegram, LetsVPN, and WhatsApp. Instead of the usual clean application plus malicious DLL pairing, the campaign inserts a second legitimate executable that is launched automatically and then abused to sideload the malicious loader, helping the activity evade detection while preserving the same final payload path. The lures were distributed through a malicious Telegram-themed website and likely through Telegram itself, with victims observed in the Philippines, Japan, Taiwan, Singapore, Hong Kong, and China, primarily among Chinese-speaking users tied to online gambling activity.
The malicious loader decrypts shellcode from files such as templateX.txt or template.txt, decompresses and loads a final payload DLL named ServerDll.dll, and executes a backdoor designed in part to steal cryptocurrency wallets, including checks for the MetaMask Chrome extension. Sophos said the malware stores configuration data in the Windows registry and supports commands for code execution, clipboard access, file download, and event log clearing, while infrastructure including nsjdhmdjs[.]com was linked to the operation. Researchers also identified debug-style payload samples on VirusTotal containing Gh0st RAT source code, indicating possible tooling overlap or code reuse in the actor’s malware development.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Sophos linked infrastructure including nsjdhmdjs[.]com to Dragon Breath and observed repeated swapping of second-stage clean executables and DLL names to evade detection while preserving the same payload chain. The researchers also found debug-style payload variants on VirusTotal containing gh0st RAT source code, suggesting tooling overlap or code reuse.
Sophos found that the malicious loader decrypted shellcode from templateX.txt or template.txt, loaded a final payload DLL named ServerDll.dll, and executed a backdoor with commands for execution, clipboard access, file download, and event log clearing. The malware also checked for the MetaMask Chrome extension, indicating a focus on cryptocurrency wallet theft.
Sophos reported a multi-stage DLL sideloading campaign linked to Operation Dragon Breath, also known as APT-Q-27 or Golden Eye Dog. The activity used fake installers such as Telegram, LetsVPN, and WhatsApp packages to target Chinese-speaking Windows users involved in online gambling across the Philippines, Japan, Taiwan, Singapore, Hong Kong, and China.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 17 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.