DragonBreath: Dragon in the Kernel
ID: c61217e7-0773-59ec-bb11-bf273e8a675e
STIX ID: report--c61217e7-0773-59ec-bb11-bf273e8a675e
Feed Name: Ransomware ISAC Blog
Date Published: 2026-04-22
Date Updated: 2026-08-21
Author: [email protected] (Alex Necula & Ellis Stannard)
**Executive Summary:** This advisory documents a critical zero-day BYOVD vulnerability in a WHQL-signed kernel driver (dragoncore_k.sys) issued to Zhengzhou 403 Network Technology Co., Ltd.; the driver exposes an unauthenticated IOCTL enabling Ring-0 termination of PPL-protected processes, fully neutralizing endpoint security. The report provides technical reverse engineering, exploitation chain, YARA detection, IOCs (file hashes, EV cert serial 4668EDFA623554CF0B48F401, C2 domain oss-aws.1nb.xyz), links to malicious droppers and MalwareBazaar samples, and attributes the activity with high confidence to Dragon Breath APT (APT-Q-27) while noting a medium-confidence personnel nexus to APT31/Wuhan Xiaoruizhi.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
