logo

DragonBreath: Dragon in the Kernel

ID: b5d2d7de-705d-5798-9d4f-0a32efc37169

STIX ID: report--b5d2d7de-705d-5798-9d4f-0a32efc37169

Feed Name: Ransomware ISAC Blog

Threat Score
92/100

Date Published: 2026-04-22

Date Updated: 2026-07-29

Author: [email protected] (Alex Necula & Ellis Stannard)

...
...

**Executive summary:** This advisory documents a critical zero‑day BYOVD vulnerability in the WHQL‑signed kernel driver dragoncore_k.sys (Zhengzhou 403), which exposes an unauthenticated IOCTL allowing Ring‑0 termination of processes (bypassing PPL/HVCI and neutralizing EDR/AV); associated signed droppers, shared CobaltStrike C2 (oss-aws.1nb.xyz), revoked EV certificate evidence, extensive IoCs, and attribution to Dragon Breath APT (APT‑Q‑27) with a medium‑confidence personnel link to APT31 are provided alongside mitigation and disclosure guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.