logo

DragonBreath: Dragon in the Kernel

ID: c61217e7-0773-59ec-bb11-bf273e8a675e

STIX ID: report--c61217e7-0773-59ec-bb11-bf273e8a675e

Feed Name: Ransomware ISAC Blog

Threat Score
90/100

Date Published: 2026-04-22

Date Updated: 2026-08-21

Author: [email protected] (Alex Necula & Ellis Stannard)

...
...

**Executive Summary:** This advisory documents a critical zero-day BYOVD vulnerability in a WHQL-signed kernel driver (dragoncore_k.sys) issued to Zhengzhou 403 Network Technology Co., Ltd.; the driver exposes an unauthenticated IOCTL enabling Ring-0 termination of PPL-protected processes, fully neutralizing endpoint security. The report provides technical reverse engineering, exploitation chain, YARA detection, IOCs (file hashes, EV cert serial 4668EDFA623554CF0B48F401, C2 domain oss-aws.1nb.xyz), links to malicious droppers and MalwareBazaar samples, and attributes the activity with high confidence to Dragon Breath APT (APT-Q-27) while noting a medium-confidence personnel nexus to APT31/Wuhan Xiaoruizhi.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.