RoningLoader Campaign Uses DLL Side-Loading, Code Injection to Slip Past Defenses
ID: 84619ca0-0bfa-5988-b440-01c6aac1c845
STIX ID: report--84619ca0-0bfa-5988-b440-01c6aac1c845
Feed Name: GBHackers
**Executive Summary:** DragonBreath (APT-Q-27) is operating a RoningLoader campaign that deploys a customized Gh0st RAT and uses DLL side-loading, CreateRemoteThread/LoadLibrary injection, service creation/abuse, privilege escalation, UAC disabling, and living‑off‑the‑land tools to maintain stealth and persistence while targeting Chinese-speaking users—particularly cryptocurrency apps and gaming VPNs; AttackIQ published an attack graph to help organizations validate defenses against these techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
