Dragon Breath (APT-Q-27) Deploys RONINGLOADER to Disable Security Tools and Drop Gh0st RAT
Dragon Breath (APT-Q-27) Deploys RONINGLOADER to Disable (TL-2026-1996), also tracked as RONINGLOADER campaign, is a high-severity malware campaign, first published 2026-08-12. It is attributed to Dragon Breath (China) with medium confidence, affects Microsoft Windows Defender Antivirus / WDAC Code Integrity policy, maps to 19 MITRE ATT&CK techniques (T1027, T1055, T1056.001), and is covered by 9 detection rules and 26 indicators of compromise.
Key facts for TL-2026-1996
- Threat ID
- TL-2026-1996
- Also known as
- RONINGLOADER campaign, Golden Gh0st RAT operation, CylindricalCanine (DigiCert incident)
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-08-12
- Last reviewed
- 2026-08-12
- Attribution
- Dragon Breath
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China
- Motivation
- FINANCIAL
- Target sectors
- online gambling, financial services, certificate authority pki
- Target regions
- china, hong kong, taiwan, singapore, japan, philippines, North America
- Detection rules
- 9
- Indicators of compromise
- 26
Malware and tooling in Dragon Breath (APT-Q-27) Deploys RONINGLOADER to Disable
Malware and tooling: DragonBreath, Ghost RAT, Golden Gh0st RAT, RONINGLOADER, Zhong Stealer
Chinese cybercrime group Dragon Breath (APT-Q-27, Golden Eye Dog/GoldenEyeDog) uses the multi-stage RONINGLOADER, a validly-signed kernel driver (ollama.sys), an unsigned WDAC policy, and ClipUp.exe/PPL abuse to blind Chinese AV/EDR tools before injecting a modified Gh0st RAT — now a WebSocket-based 'Golden Gh0st RAT' variant. In April 2026 the group's CylindricalCanine subgroup compromised DigiCert support workstations and stole EV code-signing certificates later used to sign malware including Zhong Stealer.
How Dragon Breath (APT-Q-27) Deploys RONINGLOADER to Disable works
Dragon Breath (tracked as APT-Q-27, Golden Eye Dog/GoldenEyeDog, and Miuuti Group) is a Chinese-language cybercrime APT first documented in 2020, historically distributing trojanized Telegram, LetsVPN, and WhatsApp installers via watering-hole sites and BlackSEO/malvertising to Chinese-speaking victims across China, Hong Kong, Taiwan, Singapore, Japan, and the Philippines, with a focus on the online-gambling and financial-services communities. A May 2023 Sophos report documented a 'double DLL side-loading' evolution in which a first clean application side-loads a second clean application, which in turn side-loads the malicious loader DLL — evasion of security-vendor sideloading blocklists via added indirection.
Beginning in November 2025, Elastic Security Labs documented RONINGLOADER, a substantially more sophisticated multi-stage loader distributed via trojanized NSIS installers impersonating Google Chrome and Microsoft Teams. The chain runs an MSI dropper (klklznuah.msi) that extracts nested NSIS installers, one benign and one malicious (Snieoatwtregoable.exe/.dll), which decrypts an embedded payload (tp.png) via a ROR+XOR routine and injects shellcode. The payload enumerates and terminates Chinese AV/EDR products (Microsoft Defender, Kingsoft Internet Security, Tencent PC Manager, Qihoo 360 Total Security, Huorong Security) using a validly signed kernel driver, ollama.sys (signed by Kunming Wuqi E-commerce Co., Ltd., cert valid Feb 2025–Feb 2026), which exposes IOCTL 0x222000 for privileged process termination via ZwOpenProcess/ZwTerminateProcess. Elastic pivoted on the signing certificate and found 71 additional signed binaries, suggesting a leaked/compromised code-signing credential well before the confirmed April 2026 DigiCert breach.
The loader further tampers with Windows Defender by directory-link abuse (mklink of a fake Defender Platform path) combined with Protected Process Light (PPL) abuse via ClipUp.exe -ppl (based on the August 2025 'Zero Salarium'/EDR-Freeze public disclosure), overwriting MsMpEng.exe with junk data to persistently disable Defender. It also deploys an unsigned WDAC Code Integrity policy (Enabled:Unsigned System Integrity Policy) into C:\Windows\System32\CodeIntegrity\CiPolicies\Active that deny-lists Qihoo 360 and Huorong executables (360rp.exe, 360sd.exe, 360Safe.exe, 360Tray.exe, ZhuDongFangYu.exe, ARPProte.exe, HipsMain.exe, HipsDaemon.exe, HipsTray.exe, and all Huorong-signed binaries by certificate TBS hash). Final-stage code (goldendays.dll, loaded via regsvr32.exe proxy execution and run as the service 'MicrosoftSoftware2ShadowCop4yProvider') uses thread-pool-based process injection (CreateThreadpoolWait/ZwAssociateWaitCompletionPacket, NtCreateSection/NtMapViewOfSection) into TrustedInstaller.exe, elevation_service.exe, taskhostw.exe, ctfmon.exe, RuntimeBroker.exe, sihost.exe, SecurityHealthSystray.exe, and vssvc.exe to run the final payload, a modified Gh0st RAT (6uf9i.exe), with persistence maintained by a watchdog batch script.
The Gh0st RAT variant steals browser credentials from Chrome, Firefox, 360se.exe, 360chrome.exe, and QQBrowser.exe (Login Data / FormData3.dat / history databases), logs keystrokes via DirectInput8 to microsoft.dotnet.common.log, monitors and hijacks the clipboard (including a cryptocurrency-wallet address swap function tied to C2 command ID 243, tracking MetaMask via the '狐狸系列' string), and clears Windows Event Logs. Its 2026 successor, Golden Gh0st RAT, replaces the original raw-TCP C2 with a WebSocket-based protocol over an HTTP upgrade handshake on non-standard ports (5188/5198, e.g., uu.goldeyeuu.io and api.keensie.com), using a custom encrypted frame format and RC4-keyed command decryption.
In parallel, Palo Alto Networks Unit 42 tracked two large-scale 2025 impersonation campaigns ('Campaign Trio', Feb–Mar 2025, spoofing i4tools/Youdao/DeepSeek across 2,000+ domains; 'Campaign Chorus', from May 2025, spoofing 40+ applications including QQ Music and Sogou) delivering Gh0st RAT via increasingly complex, signed-software-abusing infection chains — consistent with the same actor's evolution toward RONINGLOADER-class tooling.
In April 2026, a Dragon Breath subgroup Expel has named CylindricalCanine compromised code-signing certificate provider DigiCert. The actor contacted DigiCert's customer support via chat and delivered a ZIP disguised as a customer screenshot containing a malicious .scr executable (Golden Gh0st Loader), compromising two support-analyst workstations. Using the support portal's authenticated customer-account access function, the actor obtained initialization codes for pending EV Code Signing certificate orders, which combined with approved orders were functionally sufficient to issue certificates across multiple customer accounts. DigiCert and partner CAs subsequently revoked 60 certificates, 27 of which are explicitly linked to the actor; stolen certificates were used to sign Zhong Stealer (first documented by ANY.RUN in February 2025) and other Dragon Breath malware, extending the group's pattern of certificate abuse first inferred from the ollama.sys pivot.
MITRE ATT&CK techniques used in TL-2026-1996
Defense Evasion
T1027 Obfuscated Files or Information; T1055 Process Injection; T1218.010 System Binary Proxy Execution: Regsvr32
Collection
T1056.001 Input Capture: Keylogging
Execution
T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1204.002 User Execution: Malicious File
Command and Control
T1071.001 Application Layer Protocol: Web Protocols
Persistence
T1136.001 Create Account: Local Account; T1543.003 Create or Modify System Process: Windows Service
Discovery
T1518.001 Security Software Discovery
Privilege Escalation
T1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control
defense-impairment
T1553.002 Subvert Trust Controls: Code Signing; T1553.006 Subvert Trust Controls: Code Signing Policy Modification; T1685 Disable or Modify Tools; T1685.005 Clear Windows Event Logs; T1686 Disable or Modify System Firewall
Credential Access
T1555.003 Credentials from Password Stores: Credentials from Web Browsers
Initial Access
T1566.001 Phishing: Spearphishing Attachment
stealth
Affected products and versions in Dragon Breath (APT-Q-27) Deploys RONINGLOADER to Disable
- Microsoft — Windows Defender Antivirus / WDAC Code Integrity policy engine
Vulnerable versions: Windows 10; Windows 11; Windows Server - Qihoo 360 — 360 Total Security / 360 Safe / ZhuDongFangYu
Vulnerable versions: all versions targeted by IOCTL/CI-policy termination - Kingsoft — Kingsoft Internet Security
Vulnerable versions: all versions targeted - Tencent — Tencent PC Manager / QQ Browser
Vulnerable versions: all versions targeted - Huorong — Huorong Security (Sysdiag / ARPProte)
Vulnerable versions: all versions targeted - DigiCert — EV Code Signing certificate issuance / customer support portal
Vulnerable versions: support-portal customer-account access workflow (pre-April 2026)
Fixed in: 60 certificates revoked across 4 CAs post-incident, per Expel
Remediation for Dragon Breath (APT-Q-27) Deploys RONINGLOADER to Disable
Patches
- No CVE or vendor patch applies — this is a living-off-the-land, signed-driver, and code-signing-certificate abuse chain, not a software vulnerability; mitigation is detection- and policy-based
Immediate actions
- Block known Dragon Breath/RONINGLOADER C2 and distribution domains/IPs (qaqkongtiao.com, uu.goldeyeuu.io, api.keensie.com, nsjdhmdjs.com, telegramos.org, xiazailianjieoss.com, xiaobaituziha.com, xiaofeige.icu, yqmqhjgn.com, djbzdhygj.com, 23.225.147.227, 154.82.84.227, 95.173.197.195) at DNS/proxy/firewall
- Hunt for and quarantine ollama.sys (SHA256 2515b546125d20013237aeadec5873e6438ada611347035358059a77a32c54f5) and any other binaries signed by certificates pivoted from it or from the DigiCert April 2026 incident
- Enforce certificate revocation checking (CRL/OCSP) at endpoints and distrust the 60 certificates revoked by DigiCert/partner CAs in connection with the CylindricalCanine incident
- Alert on unsigned Code Integrity policy loads into C:\Windows\System32\CodeIntegrity\CiPolicies\Active and on ClipUp.exe invoked with -ppl against non-standard target paths (PPL/EDR-Freeze abuse pattern)
Workarounds
- Restrict kernel driver loading to an enterprise-managed allow-list so a validly-signed but unknown driver (e.g., ollama.sys) cannot load even though its certificate chain validates
- Restrict or alert on regsvr32.exe and ClipUp.exe execution via application control where not required for business use
Longer-term hardening
- Deploy EDR with PPL/ELAM tamper-detection and kernel-driver allow-listing (WDAC/HVCI) instead of relying solely on consumer AV signature detection
- Harden CA/vendor support workflows against attachment-borne compromise: sandbox all customer-submitted files in support-ticket/chat channels, remove local admin rights from support workstations, and enforce phishing-resistant MFA on any portal with authenticated customer-account access
- Monitor for thread-pool-based process injection (CreateThreadpoolWait/ZwAssociateWaitCompletionPacket, NtCreateSection/NtMapViewOfSection) targeting TrustedInstaller.exe, elevation_service.exe, vssvc.exe, and other high-trust processes
- Implement browser credential-store hardening (App-Bound Encryption / OS Credential Guard) to blunt Login Data / FormData theft handlers used by Gh0st RAT variants
Weaknesses (CWE) in Dragon Breath (APT-Q-27) Deploys RONINGLOADER to Disable
CWE-494, CWE-347
Timeline of Dragon Breath (APT-Q-27) Deploys RONINGLOADER to Disable
- Dragon Breath (APT-Q-27/Golden Eye Dog) first documented using watering-hole sites distributing trojanized Telegram installers.
- Continued abuse of fake Telegram/LetsVPN/WhatsApp installers to deploy Gh0st RAT to Chinese-speaking gambling-sector victims.
- Sophos publishes 'A doubled Dragon Breath' detailing the double-clean-app DLL side-loading evolution used against gambling-focused targets.
- Zhong Stealer, later signed with certificates stolen in the April 2026 DigiCert incident, is first documented by ANY.RUN.
- Unit 42 tracks 'Campaign Trio' — 2,000+ domains impersonating i4tools, Youdao, and DeepSeek to deliver Gh0st RAT via MSI droppers.
- Unit 42 tracks 'Campaign Chorus' — 40+ impersonated applications (QQ Music, Sogou, etc.) using VBScript droppers and DLL side-loading (wsc_proxy.exe/wsc.dll).
- Zero Salarium publicly discloses the ClipUp.exe PPL-abuse (EDR-Freeze) technique that RONINGLOADER adopts within weeks.
- Elastic Security Labs identifies a live RONINGLOADER campaign via telemetry-based threat hunting, distributed through trojanized Chrome/Teams NSIS installers.
- Elastic Security Labs publishes 'RONINGLOADER: DragonBreath's New Path to PPL Abuse,' detailing the ollama.sys driver, WDAC policy abuse, and full IOC set.
- Continued RONINGLOADER activity identified into January 2026, per subsequent reporting on the GoldenEyeDog cluster.
- CylindricalCanine subgroup compromises two DigiCert support-analyst workstations via a malicious .scr disguised as a customer screenshot sent through DigiCert's support chat, then abuses the support portal to obtain EV Code Signing certificate initialization codes.
- Expel publishes 'Introducing CylindricalCanine,' attributing the April 2026 DigiCert breach to a GoldenEyeDog/Dragon Breath subgroup; DigiCert and partner CAs revoke 60 certificates (27 explicitly linked to the actor).
- Picus Security publishes a consolidated Dragon Breath/RONINGLOADER/Gh0st RAT/DigiCert writeup synthesizing the Elastic, Sophos, and Expel reporting.
Sources cited for Dragon Breath (APT-Q-27) Deploys RONINGLOADER to Disable
- Dragon Breath (APT-Q-27): RONINGLOADER and Gh0st RAT Explained
- RONINGLOADER: DragonBreath's New Path to PPL Abuse
- A doubled "Dragon Breath" adds new air to DLL sideloading attacks
- Introducing CylindricalCanine: The GoldenEyeDog subgroup responsible for the April DigiCert incident
- GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
- Dragon Breath Uses RONINGLOADER to Disable Security Tools and Deploy Gh0st RAT
- Digital Doppelgangers: Anatomy of Evolving Impersonation Campaigns Distributing Gh0st RAT
Threats related to Dragon Breath (APT-Q-27) Deploys RONINGLOADER to Disable
Detection coverage for TL-2026-1996
As of 2026-08-12, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1996 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.