Emulating the Multi-Stage RoningLoader Malware
ID: c1be4144-1ba4-5a93-abf1-2b72ab5c3be5
STIX ID: report--c1be4144-1ba4-5a93-abf1-2b72ab5c3be5
Feed Name: Security Boulevard
Threat Score
AttackIQ published an adversary-emulation for DragonBreath (APT‑Q‑27) / RoningLoader that models post-compromise TTPs—including execution, persistence, privilege escalation, defense evasion, and discovery—based on observed campaigns targeting Chinese-speaking users (notably cryptocurrency and gaming VPN software) and aims to help organizations validate detection and prevention controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
