Dragon Breath (APT-Q-27) Deploys RONINGLOADER to Disable Security Tools and Drop Gh0st RAT — Threadlinqs Intelligence
As of 2026-08-12, Dragon Breath (APT-Q-27) Deploys RONINGLOADER to Disable Security Tools and Drop Gh0st RAT is a high-severity malware threat attributed to Dragon Breath (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 26 indicators of compromise.
Threat ID: TL-2026-1996 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Dragon Breath · China · FINANCIAL
Chinese cybercrime group Dragon Breath (APT-Q-27, Golden Eye Dog/GoldenEyeDog) uses the multi-stage RONINGLOADER, a validly-signed kernel driver (ollama.sys), an unsigned WDAC policy, and
Dragon Breath (tracked as APT-Q-27, Golden Eye Dog/GoldenEyeDog, and Miuuti Group) is a Chinese-language cybercrime APT first documented in 2020, historically distributing trojanized Telegram, LetsVPN, and WhatsApp installers via watering-hole sites and BlackSEO/malvertising to Chinese-speaking victims across China, Hong Kong, Taiwan, Singapore, Japan, and the Philippines, with a focus on the online-gambling and financial-services communities. A May 2023 Sophos report documented a 'double DLL side-loading' evolution in which a first clean application side-loads a second clean application, which in turn side-loads the malicious loader DLL — evasion of security-vendor sideloading blocklists via added indirection.
Beginning in November 2025, Elastic Security Labs documented RONINGLOADER, a substantially more sophisticated multi-stage loader distributed via trojanized NSIS installers impersonating Google Chrome and Microsoft Teams. The chain runs an MSI dropper (klklznuah.msi) that extracts nested NSIS installers, one benign and one malicious (Snieoatwtregoable.exe/.dll), which decrypts an embedded payload (tp.png) via a ROR+XOR routine and injects shellcode. The payload enumerates and terminates Chinese AV/EDR products (Microsoft Defender, Kingsoft Internet Security, Tencent PC Manager, Qihoo 360 Total Security, Huorong Security) using a validly signed kernel driver, ollama.sys (signed by Kunming Wuqi E-commerce Co., Ltd., cert valid Feb 2025–Feb 2026), which exposes IOCTL 0x222000 for privileged process termination via ZwOpenProcess/ZwTerminateProcess. Elastic pivoted on the signing certificate and found 71 additional signed binaries, suggesting a leaked/compromised code-signing credential well before the confirmed April 2026 DigiCert breach.
The loader further tampers with Windows Defender by directory-link abuse (mklink of a fake Defender Platform path) combined with Protected Process Light (PPL) abuse via ClipUp.exe -ppl (based on the August 2025 'Zero Salarium'/EDR-Freeze public disclosure), overwriting MsMpEng.exe with junk data to persistently disable Defender. It also deploys an unsigned WDAC Code Integrity policy (Enabled:Unsigned System Integrity Policy) into C:\Windows\System32\CodeIntegrity\CiPolicies\Active that deny-lists Qihoo 360 and Huorong executables (360rp.exe, 360sd.exe, 360Safe.exe, 360Tray.exe, ZhuDongFangYu.exe, ARPProte.exe, HipsMain.exe, HipsDaemon.exe, HipsTray.exe, and all Huorong-signed binaries by certificate TBS hash). Final-stage code (goldendays.dll, loaded via regsvr32.exe proxy execution and run as the service 'MicrosoftSoftware2ShadowCop4yProvider') uses thread-pool-based process injection (CreateThreadpoolWait/ZwAssociateWaitCompletionPacket, NtCreateSection/NtMapViewOfSection) into TrustedInstaller.exe, elevation_service.exe, taskhostw.exe, ctfmon.exe, RuntimeBroker.exe, sihost.exe, SecurityHealthSystray.exe, and vssvc.exe to run the final payload, a modified Gh0st RAT (6uf9i.exe), with persistence maintained by a watchdog batch script.
The Gh0st RAT variant steals browser credentials from Chrome, Firefox, 360se.exe, 360chrome.exe, and QQBrowser.exe (Login Data / FormData3.dat / history databases), logs keystrokes via DirectInput8 to microsoft.dotnet.common.log, monitors and hijacks the clipboard (including a cryptocurrency-wallet address swap function tied to C2 command ID 243, tracking MetaMask via the '狐狸系列' string), and clears Windows Event Logs. Its 2026 successor, Golden Gh0st RAT, replaces the original raw-TCP C2 with a WebSocket-based protocol over an HTTP upgrade handshake on non-standard ports (5188/5198, e.g., uu.goldeyeuu.io and api.keensie.com), using a custom encrypted frame format and RC4-keyed command decryption.
In parallel, Palo Alto Networks Unit 42 tracked two large-scale 2025 impersonation campaigns ('Campaign Trio', Feb–Mar 2025, spoofing i4tools/Youdao/DeepSeek across 2,000+ domains; 'Campaign Chorus', from May 2025, spoofing 40+ applications including QQ Music and
Weaknesses (CWE)
CWE-494, CWE-347
Target sectors: online gambling, financial services, certificate authority pki
Target regions: china, hong kong, taiwan, singapore, japan, philippines, North America
Timeline
- Dragon Breath (APT-Q-27/Golden Eye Dog) first documented using watering-hole sites distributing trojanized Telegram installers.
- Continued abuse of fake Telegram/LetsVPN/WhatsApp installers to deploy Gh0st RAT to Chinese-speaking gambling-sector victims.
- Sophos publishes 'A doubled Dragon Breath' detailing the double-clean-app DLL side-loading evolution used against gambling-focused targets.
- Zhong Stealer, later signed with certificates stolen in the April 2026 DigiCert incident, is first documented by ANY.RUN.
- Unit 42 tracks 'Campaign Trio' — 2,000+ domains impersonating i4tools, Youdao, and DeepSeek to deliver Gh0st RAT via MSI droppers.
- Unit 42 tracks 'Campaign Chorus' — 40+ impersonated applications (QQ Music, Sogou, etc.) using VBScript droppers and DLL side-loading (wsc_proxy.exe/wsc.dll).
- Zero Salarium publicly discloses the ClipUp.exe PPL-abuse (EDR-Freeze) technique that RONINGLOADER adopts within weeks.
- Elastic Security Labs identifies a live RONINGLOADER campaign via telemetry-based threat hunting, distributed through trojanized Chrome/Teams NSIS installers.
- Elastic Security Labs publishes 'RONINGLOADER: DragonBreath's New Path to PPL Abuse,' detailing the ollama.sys driver, WDAC policy abuse, and full IOC set.
- Continued RONINGLOADER activity identified into January 2026, per subsequent reporting on the GoldenEyeDog cluster.
- CylindricalCanine subgroup compromises two DigiCert support-analyst workstations via a malicious .scr disguised as a customer screenshot sent through DigiCert's support chat, then abuses the support portal to obtain EV Code Signing certificate initialization codes.
- Expel publishes 'Introducing CylindricalCanine,' attributing the April 2026 DigiCert breach to a GoldenEyeDog/Dragon Breath subgroup; DigiCert and partner CAs revoke 60 certificates (27 explicitly linked to the actor).
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 26 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566.001, T1204.002, T1218.010, T1059.003, T1543.003, T1136.001, T1574.001, T1548.002, T1055, T1685