logo

Dragon in the Kernel — Part II

ID: 59ec9b3d-33f6-5f0c-8260-e8ae185e8f19

STIX ID: report--59ec9b3d-33f6-5f0c-8260-e8ae185e8f19

Feed Name: Ransomware ISAC Blog

Threat Score
90/100

Date Published: 2026-04-29

Date Updated: 2026-08-21

Author: [email protected] (Alex Necula & Ellis Stannard)

...
...

**Executive summary:** This report expands prior research by documenting multi-source confirmation that Zhengzhou 403 Network Technology abused consecutive GlobalSign EV code-signing certificates to deploy a layered kernel-level offensive toolkit (dragoncore_k.sys, hide_process, YDArkDrv.sys) alongside trojanized droppers running CobaltStrike (C2: oss-aws.1nb.xyz); independent researcher Squiblydoo revealed a prior January 2024 certificate, additional signed drivers and hashes, provided certificate/thumbprint IOCs, and initiated a GlobalSign revocation that curtailed the 2025 certificate's operational window.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.