ThreatCluster

DragonBreath APT Launches RoningLoader Malware Campaign Targeting Chinese Users

First seen 9 Apr 2026, 08:01 UTC GbhackersCybersecuritynews 67

Article Content

Browse articles
ThreatCluster

The DragonBreath group, also known as APT-Q-27, has initiated a new campaign utilizing RoningLoader malware, which employs advanced techniques such as DLL side-loading and code injection to evade security measures. This campaign primarily targets Chinese-speaking users by masquerading as legitimate applications like Google Chrome and Microsoft Teams. Active since at least 2022, DragonBreath has progressively enhanced its tactics, making detection increasingly difficult. The malware's multi-stage loader approach allows it to infiltrate systems without raising alarms. Reports indicate that the campaign has been linked to espionage activities, although specific numbers of affected users or systems have not been disclosed. The current status of the campaign suggests ongoing operations, with security firms monitoring its developments closely.

Key Points: • DragonBreath APT is behind the RoningLoader malware campaign targeting Chinese-speaking users. • The malware uses DLL side-loading and code injection to bypass traditional security defenses. • RoningLoader disguises itself as trusted applications like Google Chrome and Microsoft Teams.

Timeline

2022-01-01
DragonBreath APT begins operations with RoningLoader.
2022-12-01
QianXin and Sophos document earlier campaigns by DragonBreath.
2026-04-09
Gbhackers and Cybersecuritynews report on the latest RoningLoader campaign.