logo

Emulating the Multi-Stage RoningLoader Malware

ID: c1be4144-1ba4-5a93-abf1-2b72ab5c3be5

STIX ID: report--c1be4144-1ba4-5a93-abf1-2b72ab5c3be5

Feed Name: Security Boulevard

Threat Score
75/100

Date Published: 2026-04-07

Date Updated: 2026-04-22

Author: Ayelen Torello

...
...

AttackIQ published an adversary-emulation for DragonBreath (APT‑Q‑27) / RoningLoader that models post-compromise TTPs—including execution, persistence, privilege escalation, defense evasion, and discovery—based on observed campaigns targeting Chinese-speaking users (notably cryptocurrency and gaming VPN software) and aims to help organizations validate detection and prevention controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.