#RoningLoader
Dragon Breath Uses RONINGLOADER to Disable Security Tools and Deploy Gh0st RAT
Dragon Breath Uses RONINGLOADER to Disable Security Tools and Deploy Gh0st RAT
Gh0st RAT spreads through Dragon Breath and large-scale impersonation campaigns using multi-stage loaders and evasive NSIS installers targeting Chines
share.google
November 17, 2025 at 8:31 PM
RONINGLOADER Weaponizes Signed Drivers to Disable Defender and Evade EDR Tools
RONINGLOADER Weaponizes Signed Drivers to Disable Defender and Evade EDR Tools
RONINGLOADER spreads via fake installers, bypasses antivirus, and delivers a modified gh0st RAT, disabling Windows Defender.
cybersecuritynews.com
November 15, 2025 at 12:58 PM
DragonBreath (APT-Q-27) targets Chinese-speaking users with a modified gh0st RAT variant focused on crypto and gaming VPNs since 2022. AttackIQ’s RoningLoader emulation aids detection and testing. #China #RoningLoader #APTQ27
Emulating the Multi-Stage RoningLoader Malware
DragonBreath (APT-Q-27) is a persistent, evolving threat actor targeting Chinese-speaking users with a modified variant of the open-source gh0st RAT and has focused on cryptocurrency-related and gaming VPN software since at least 2022. AttackIQ published a RoningLoader emulation in its AEV platform to reproduce the group's post-compromise TTPs and help organizations...
www.hendryadrian.com
April 14, 2026 at 11:45 PM
A validly-signed driver silently kills your AV before Gh0st RAT moves in over WebSocket C2. https://intel.threadlinqs.com/threat/TL-2026-1996 #ThreatIntel #RONINGLOADER #Golden #Zhong
August 12, 2026 at 4:34 PM
Elastic finds RONINGLOADER: trojanized NSIS installers, signed driver ollama.sys, PPL (ClipUp) abuse to tamper with Defender, custom WDAC blocking 360/Huorong, and thread-pool injection; linked to DragonBreath. #RONINGLOADER #PPL #WDAC https://bit.ly/47TE0Pa
November 18, 2025 at 8:16 PM
RONINGLOADER: DragonBreath’s New Path to PPL Abuse
RONINGLOADER: DragonBreath’s New Path to PPL Abuse
www.elastic.co
November 14, 2025 at 5:39 PM
Emulating the Multi-Stage RoningLoader Malware

AttackIQ has released a new assessment template that emulates the behaviors of RoningLoader, a multi-stage loader observed in recent intrusion campaigns. RoningLoader operates through a layered execution chain, enabling stealthy deli…
#hackernews #news
Emulating the Multi-Stage RoningLoader Malware
AttackIQ has released a new assessment template that emulates the behaviors of RoningLoader, a multi-stage loader observed in recent intrusion campaigns. RoningLoader operates through a layered execution chain, enabling stealthy delivery and execution of follow-on payloads while evading traditional detection mechanisms.
securityboulevard.com
April 8, 2026 at 12:16 PM
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 72

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Contagious Interview Actors Now Utilize JSON Storage Services for Malware Del…
#gpt #hackernews #news
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 72
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Contagious Interview Actors Now Utilize JSON Storage Services for Malware Delivery RONINGLOADER: DragonBreath’s New Path to PPL Abuse   npm Malware Campaign Uses Adspect Cloaking to Deliver Malicious Redirects  GPT Trade: Fake Google Play Store […]
securityaffairs.com
November 24, 2025 at 1:41 PM
Dragon Breath Uses RONINGLOADER to Disable Security Tools and Deploy Gh0st RAT

The threat actor known as Dragon Breath has been observed making use of a multi-stage loader codenamed RONINGLOADER to deliver a modified variant of a remote access trojan called Gh0st RAT.
…
#hackernews #microsoft #news
Dragon Breath Uses RONINGLOADER to Disable Security Tools and Deploy Gh0st RAT
The threat actor known as Dragon Breath has been observed making use of a multi-stage loader codenamed RONINGLOADER to deliver a modified variant of a remote access trojan called Gh0st RAT. The campaign, which is primarily aimed at Chinese-speaking users, employs trojanized NSIS installers masquerading as legitimate like Google Chrome and Microsoft Teams, according to Elastic Security Labs. "The
thehackernews.com
November 18, 2025 at 3:55 AM
Dragon Breath APT Revives Gh0st RAT via RONINGLOADER: A Deep‑Dive

Introduction A sophisticated cyber‑espionage campaign has resurfaced, now linked to a threat actor known as Dragon Breath, which has deployed a new loader dubbed RONINGLOADER. This campaign aims squarely at Chinese-speaking users,…
Dragon Breath APT Revives Gh0st RAT via RONINGLOADER: A Deep‑Dive
Introduction A sophisticated cyber‑espionage campaign has resurfaced, now linked to a threat actor known as Dragon Breath, which has deployed a new loader dubbed RONINGLOADER. This campaign aims squarely at Chinese-speaking users, distributing a modified version of the notorious Gh0st RAT via trojanized installers masquerading as legitimate software — such as Google Chrome and Microsoft Teams. The campaign's sophistication lies in its ability to disable security defenses and evade detection using a multi-stage process that abuses signed drivers and Windows protection mechanisms.
undercodenews.com
November 17, 2025 at 3:39 PM
Emulating the Multi-Stage RoningLoader Malware https://packetstorm.news/news/view/41114 #news
April 9, 2026 at 5:30 PM
Unmasking RoningLoader: The Stealthy Malware Evolution You Can’t Afford to Ignore

Introduction: The cybersecurity landscape is witnessing a sophisticated evolution in malware delivery mechanisms, with RoningLoader emerging as a prime example. This advanced threat utilizes a multi-stage, fileless…
Unmasking RoningLoader: The Stealthy Malware Evolution You Can’t Afford to Ignore
Introduction: The cybersecurity landscape is witnessing a sophisticated evolution in malware delivery mechanisms, with RoningLoader emerging as a prime example. This advanced threat utilizes a multi-stage, fileless attack chain to bypass traditional defenses, posing a significant risk to organizations worldwide. Security professionals must understand its intricate obfuscation and execution techniques to effectively detect and neutralize this persistent danger. Learning Objectives:
undercodetesting.com
November 15, 2025 at 9:36 PM
RONINGLOADER weaponizes Signed Drivers to disable Defender and evade EDR Tools:

cybersecuritynews.com/roningloader...
November 17, 2025 at 6:52 AM
Feed: "Cyber Security News"
By: Varshini on Thursday, April 9, 2026
RoningLoader Attack Chain Combines DLL Side-Loading With Code Injection
Cybersecurity researchers at AttackIQ have developed a new attack graph to simulate the advanced tactics and procedures used by the
cyberpress.org
April 10, 2026 at 3:27 AM
Feed: "The Hacker News"
By: info@thehackernews.com (The Hacker News) on Monday, November 17, 2025
Dragon Breath Uses RONINGLOADER to Disable Security Tools and Deploy Gh0st RAT
Gh0st RAT spreads through Dragon Breath and large-scale impersonation campaigns using multi-stage loaders and evasive NSIS installers targeting Chines
thehackernews.com
November 17, 2025 at 8:09 PM
Feed: "Cyber Security News"
By: Tushar Subhra Dutta on Saturday, November 15, 2025
RONINGLOADER Weaponizes Signed Drivers to Disable Defender and Evade EDR Tools
RONINGLOADER spreads via fake installers, bypasses antivirus, and delivers a modified gh0st RAT, disabling Windows Defender.
cybersecuritynews.com
November 15, 2025 at 6:39 PM
Feed: "GBHackers Security | #1 Globally Trusted Cyber Security News Platform"
By: Mayura Kathir on Friday, November 14, 2025
RONINGLOADER Uses Signed Drivers to Disable Microsoft Defender and Bypass EDR
Elastic Security Labs has uncovered a sophisticated campaign deploying a newly identified loader, dubbed RONINGLOADER.
gbhackers.com
November 15, 2025 at 8:25 AM
Dragon Breath APT group employs RONINGLOADER to disable security tools and deploy Gh0st RAT. Stay vigilant! #CyberSecurity #APT #Gh0stRAT #RONINGLOADER Link: thedailytechfeed.com/dragon-breat...
November 18, 2025 at 3:04 PM
Beware of RONINGLOADER: This stealthy malware uses signed drivers to disable security tools and evade detection. Stay vigilant and ensure your software sources are trustworthy. #CyberSecurity #MalwareAlert #RONINGLOADER Link: thedailytechfeed.com/new-malware-...
November 17, 2025 at 4:30 PM
Dragon Breath Uses RONINGLOADER to Disable Security Tools and Deploy Gh0st RAT https://thehackernews.com/2025/11/dragon-breath-uses-roningloader-to.html
November 17, 2025 at 12:47 PM
#Kesakode updated to 1.0.45 !

● New malware entries: Fullmetal, Laplas, RoningLoader, ShadowRat, Silentsweeper and SystemShock
● Updated malware entries: 29
● FP-fixed signatures: 931
● 16587 new clean programs whitelisted
● 3452882 new functions
● 165257 new strings
November 16, 2025 at 9:19 AM
Dragon BreathがRONINGLOADERを利用してセキュリティツールを無効化し、Gh0st RATを展開

Dragon Breathとして知られる脅威アクターが、RONINGLOADERというコードネームの多段ローダーを利用し、リモートアクセス型トロイの木馬「Gh0st RAT」の改変バージョンを配布していることが確認されました。 このキャンペーンは主に中国語話者を標的としており、Elastic Security Labsによると、Google ChromeやMicrosoft Teamsなどの正規ソフトを装ったトロイ化されたNSISインストーラーが使われています。…
Dragon BreathがRONINGLOADERを利用してセキュリティツールを無効化し、Gh0st RATを展開
Dragon Breathとして知られる脅威アクターが、RONINGLOADERというコードネームの多段ローダーを利用し、リモートアクセス型トロイの木馬「Gh0st RAT」の改変バージョンを配布していることが確認されました。 このキャンペーンは主に中国語話者を標的としており、Elastic Security Labsによると、Google ChromeやMicrosoft Teamsなどの正規ソフトを装ったトロイ化されたNSISインストーラーが使われています。 「感染チェーンは多段階の配布メカニズムを採用しており、さまざまな回避技術を駆使し、中国市場で人気のエンドポイントセキュリティ製品を無効化するための多くの冗長性が組み込まれています」と、セキュリティ研究者のJia Yu Chan氏とSalim Bitam氏は述べています。「これには、正規署名済みドライバーの持ち込み、カスタムWDACポリシーの展開、PPL(Protected Process Light)悪用によるMicrosoft Defenderバイナリの改ざんなどが含まれます。」 Dragon Breath(APT-Q-27、Golden Eyeとも呼ばれる)は、2023年5月にSophosによって、フィリピン、日本、台湾、シンガポール、香港、中国のユーザーを標的とした攻撃で、ダブルディップDLLサイドローディングという手法を用いたキャンペーンとの関連で取り上げられました。 このハッキンググループは少なくとも2020年から活動しているとみられ、オンラインゲームやギャンブル業界を攻撃していることで知られる中国語話者の大規模な組織「Miuuti Group」と関連付けられています。 Elastic Security Labsが記録した最新のキャンペーンでは、信頼されたアプリケーションの悪意あるNSISインストーラーが、さらに2つの埋め込みNSISインストーラーの起点となります。そのうちの1つ(「letsvpnlatest.exe」)は無害で、正規ソフトウェアをインストールします。2つ目のNSISバイナリ(「Snieoatwtregoable.exe」)が、攻撃チェーンを密かに起動する役割を担います。 この過程では、DLLと暗号化ファイル(「tp.png」)が配布され、前者が疑似PNG画像の内容を読み取り、別のバイナリをメモリ上で起動するためのシェルコードを抽出します。 RONINGLOADERは、新しい「ntdll.dll」をロードすることでユーザーランドフックを除去しようとするほか、runasコマンドを利用して権限昇格を試み、Microsoft Defender Antivirus、Kingsoft Internet Security、Tencent PC Manager、Qihoo 360 Total Securityなどのハードコードされたアンチウイルス関連ソリューションのプロセスリストをスキャンします。 マルウェアはこれらの特定されたプロセスを終了させます。もし特定されたプロセスがQihoo 360 Total Security(例:「360tray.exe」「360Safe.exe」「ZhuDongFangYu.exe」)に関連している場合は、異なるアプローチを取ります。このステップには以下の一連の動作が含まれます。 ファイアウォールの設定を変更して全てのネットワーク通信をブロック Volume Shadow Copy(VSS)サービスに関連するプロセス(vssvc.exe)にシェルコードをインジェクト。ただし、その前にSeDebugPrivilegeトークンを自らに付与 VSSサービスを開始し、そのプロセスIDを取得 PoolPartyと呼ばれる手法でVSSサービスプロセスにシェルコードをインジェクト 署名済みドライバー「ollama.sys」を読み込み、「xererre1」という一時サービスを使って3つのプロセスを終了 ファイアウォール設定を元に戻す
blackhatnews.tokyo
November 17, 2025 at 12:00 PM
Dragon Breath Uses RONINGLOADER to Disable Security Tools and Deploy Gh0st RAT The threat actor known as Dragon Breath has been observed making use of a multi-stage loader codenamed RONINGLOADER to...

Origin | Interest | Match
November 17, 2025 at 12:11 PM