logo

New RoningLoader Campaign Uses DLL Side-Loading and Code Injection to Evade Detection

ID: ad8ad48b-9da3-58a1-bbb0-8e59754fa9b9

STIX ID: report--ad8ad48b-9da3-58a1-bbb0-8e59754fa9b9

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-04-09

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

RoningLoader is a multi-stage, technically sophisticated loader used by APT DragonBreath to target Chinese-speaking users across East and Southeast Asia; it abuses trojanized NSIS installers, DLL side‑loading, in-memory payloads, and a signed kernel driver to disable multiple security products and ultimately deploy a modified gh0st RAT for espionage and data theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.