Dragon in the Kernel — Part II
ID: 59ec9b3d-33f6-5f0c-8260-e8ae185e8f19
STIX ID: report--59ec9b3d-33f6-5f0c-8260-e8ae185e8f19
Feed Name: Ransomware ISAC Blog
Date Published: 2026-04-29
Date Updated: 2026-08-21
Author: [email protected] (Alex Necula & Ellis Stannard)
**Executive summary:** This report expands prior research by documenting multi-source confirmation that Zhengzhou 403 Network Technology abused consecutive GlobalSign EV code-signing certificates to deploy a layered kernel-level offensive toolkit (dragoncore_k.sys, hide_process, YDArkDrv.sys) alongside trojanized droppers running CobaltStrike (C2: oss-aws.1nb.xyz); independent researcher Squiblydoo revealed a prior January 2024 certificate, additional signed drivers and hashes, provided certificate/thumbprint IOCs, and initiated a GlobalSign revocation that curtailed the 2025 certificate's operational window.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
