Dragon Breath (APT-Q-27): RONINGLOADER and Gh0st RAT Explained
ID: a76a009c-c16e-5058-9da3-d919458eed06
STIX ID: report--a76a009c-c16e-5058-9da3-d919458eed06
Feed Name: Picus Security Articles
**Dragon Breath (APT-Q-27 / Golden Eye Dog)** is a Chinese cybercrime APT active since 2020 that targets Chinese-speaking organizations across the Asia‑Pacific region; it uses trojanized installers, double-clean-app DLL side‑loading, signed kernel drivers, Protected Process Light abuse, thread-pool and process injection to deploy loaders and a modified Gh0st RAT (RONINGLOADER) with WebSocket C2, disables regional security tools, harvests browser credentials and keylogs, and in 2026 leveraged a compromise at a certificate provider to sign malware, with recommended simulation/testing using the Picus platform.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
