DragonBreath: Dragon in the Kernel
ID: b5d2d7de-705d-5798-9d4f-0a32efc37169
STIX ID: report--b5d2d7de-705d-5798-9d4f-0a32efc37169
Feed Name: Ransomware ISAC Blog
Date Published: 2026-04-22
Date Updated: 2026-07-29
Author: [email protected] (Alex Necula & Ellis Stannard)
**Executive summary:** This advisory documents a critical zero‑day BYOVD vulnerability in the WHQL‑signed kernel driver dragoncore_k.sys (Zhengzhou 403), which exposes an unauthenticated IOCTL allowing Ring‑0 termination of processes (bypassing PPL/HVCI and neutralizing EDR/AV); associated signed droppers, shared CobaltStrike C2 (oss-aws.1nb.xyz), revoked EV certificate evidence, extensive IoCs, and attribution to Dragon Breath APT (APT‑Q‑27) with a medium‑confidence personnel link to APT31 are provided alongside mitigation and disclosure guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
