logo

Dragon Breath (APT-Q-27): RONINGLOADER and Gh0st RAT Explained

ID: a76a009c-c16e-5058-9da3-d919458eed06

STIX ID: report--a76a009c-c16e-5058-9da3-d919458eed06

Feed Name: Picus Security Articles

Threat Score
88/100

Date Published: 2026-08-12

Date Updated: 2026-08-12

Author: [email protected] (Umut Bayram)

...
...

**Dragon Breath (APT-Q-27 / Golden Eye Dog)** is a Chinese cybercrime APT active since 2020 that targets Chinese-speaking organizations across the Asia‑Pacific region; it uses trojanized installers, double-clean-app DLL side‑loading, signed kernel drivers, Protected Process Light abuse, thread-pool and process injection to deploy loaders and a modified Gh0st RAT (RONINGLOADER) with WebSocket C2, disables regional security tools, harvests browser credentials and keylogs, and in 2026 leveraged a compromise at a certificate provider to sign malware, with recommended simulation/testing using the Picus platform.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.