logo

RoningLoader Campaign Uses DLL Side-Loading, Code Injection to Slip Past Defenses

ID: 84619ca0-0bfa-5988-b440-01c6aac1c845

STIX ID: report--84619ca0-0bfa-5988-b440-01c6aac1c845

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-04-09

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

**Executive Summary:** DragonBreath (APT-Q-27) is operating a RoningLoader campaign that deploys a customized Gh0st RAT and uses DLL side-loading, CreateRemoteThread/LoadLibrary injection, service creation/abuse, privilege escalation, UAC disabling, and living‑off‑the‑land tools to maintain stealth and persistence while targeting Chinese-speaking users—particularly cryptocurrency apps and gaming VPNs; AttackIQ published an attack graph to help organizations validate defenses against these techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.