logo

RONINGLOADER: DragonBreath’s New Path to PPL Abuse

ID: 214fae9a-7ed9-5a47-a2b8-3d4631cd3314

STIX ID: report--214fae9a-7ed9-5a47-a2b8-3d4631cd3314

Feed Name: Elastic Security Labs

Threat Score
90/100

Date Published: 2025-11-15

Date Updated: 2026-04-27

...
...

Elastic Security Labs documents a sophisticated, active multi-stage campaign attributed to DragonBreath (APT-Q-27) deploying a modified gh0st RAT via trojanized NSIS installers. The loader, named RONINGLOADER, employs a signed kernel driver to terminate security processes, abuses Protected Process Light (PPL) to disable Microsoft Defender, writes an unsigned WDAC policy to block Chinese AV products, uses advanced injection techniques (thread-pool remote execution, section mapping), and deploys a final RAT with keylogging, clipboard hijacking, and remote command capabilities; the report includes extensive IOCs, YARA rules, and detection/mitigation notes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.