New RoningLoader Campaign Uses DLL Side-Loading and Code Injection to Evade Detection
ID: ad8ad48b-9da3-58a1-bbb0-8e59754fa9b9
STIX ID: report--ad8ad48b-9da3-58a1-bbb0-8e59754fa9b9
Feed Name: cybersecurityNews.com
Threat Score
RoningLoader is a multi-stage, technically sophisticated loader used by APT DragonBreath to target Chinese-speaking users across East and Southeast Asia; it abuses trojanized NSIS installers, DLL side‑loading, in-memory payloads, and a signed kernel driver to disable multiple security products and ultimately deploy a modified gh0st RAT for espionage and data theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
