Skip to content
ThreatCluster

DragonBreath APT Launches RoningLoader Malware Campaign Targeting Chinese Users

First seen 9 Apr 2026, 08:01 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •April 10, 2026 at 07:44 UTC

The DragonBreath group, also known as APT-Q-27, has initiated a new campaign utilizing RoningLoader malware, which employs advanced techniques such as DLL side-loading and code injection to evade security measures. This campaign primarily targets Chinese-speaking users by masquerading as legitimate applications like Google Chrome and Microsoft Teams. Active since at least 2022, DragonBreath has progressively enhanced its tactics, making detection increasingly difficult. The malware's multi-stage loader approach allows it to infiltrate systems without raising alarms. Reports indicate that the campaign has been linked to espionage activities, although specific numbers of affected users or systems have not been disclosed. The current status of the campaign suggests ongoing operations, with security firms monitoring its developments closely.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 184d ago How this analysis works

Timeline

2022-01-01
DragonBreath APT begins operations with RoningLoader.
2022-12-01
QianXin and Sophos document earlier campaigns by DragonBreath.
2026-04-09
Gbhackers and Cybersecuritynews report on the latest RoningLoader campaign.

More articles in this cluster (2)

Following this threat?

Track DragonBreath and Roningloader in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed