logo

Dragon in the Kernel — Part II

ID: 3b8b5a41-a7eb-5bd1-be22-829cd5013173

STIX ID: report--3b8b5a41-a7eb-5bd1-be22-829cd5013173

Feed Name: Ransomware ISAC Blog

Threat Score
90/100

Date Published: 2026-04-29

Date Updated: 2026-07-29

Author: [email protected] (Alex Necula & Ellis Stannard)

...
...

Squiblydoo's independent Cert Graveyard disclosure expands Ransom-ISAC's DragonBreath findings by showing Zhengzhou 403 used consecutive GlobalSign EV certificates (Jan 2024 and Mar 2025) to sign a layered kernel offensive stack—dragoncore_k.sys (EDR kill/spoof), a GitHub-derived hide_process driver (EPROCESS unlinking), and YDArkDrv.sys (full rootkit)—plus CobaltStrike droppers; multi-source confirmation, IOCs (file hashes, certificate thumbprints, C2 domain oss-aws.1nb.xyz), and a triggered GlobalSign revocation are documented, indicating a deliberate, long-running, high-risk malicious signing operation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.