Skip to content

New RoningLoader Campaign Uses DLL Side

Cybersecuritynews •Tushar Subhra Dutta • April 9, 2026

A threat actor known as DragonBreath has launched a stealthy campaign using a multi-stage malware loader called RoningLoader. The malware targets Chinese-speaking users by disguising itself as trusted software such as Google Chrome and Microsoft Teams. Its core strength lies in a layered approach to avoiding detection — combining DLL side-loading, code injection, and signed […]