DragonBreath APT Launches RoningLoader Malware Campaign Targeting Chinese Users
Article Content
- •DragonBreath APT is behind the RoningLoader malware campaign targeting Chinese-speaking users.
- •The malware uses DLL side-loading and code injection to bypass traditional security defenses.
- •RoningLoader disguises itself as trusted applications like Google Chrome and Microsoft Teams.
The DragonBreath group, also known as APT-Q-27, has initiated a new campaign utilizing RoningLoader malware, which employs advanced techniques such as DLL side-loading and code injection to evade security measures. This campaign primarily targets Chinese-speaking users by masquerading as legitimate applications like Google Chrome and Microsoft Teams. Active since at least 2022, DragonBreath has progressively enhanced its tactics, making detection increasingly difficult. The malware's multi-stage loader approach allows it to infiltrate systems without raising alarms. Reports indicate that the campaign has been linked to espionage activities, although specific numbers of affected users or systems have not been disclosed. The current status of the campaign suggests ongoing operations, with security firms monitoring its developments closely.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track DragonBreath and Roningloader in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…