Malware, Threat Intelligence

Novel RONINGLOADER loader leveraged in Dragon Breath APT attacks

Privacy concept: pixelated words Malware on digital background, 3d render

Attacks with the multi-stage RONINGLOADER payload have been launched by the advanced persistent threat operation Dragon Breath to facilitate updated Gh0st RAT malware deployment as part of a campaign mostly aimed at Chinese speakers, The Hacker News reports.

Dragon Breath, also known as Golden Eye and APT-Q-27, leveraged trojanized NSIS installers spoofing Microsoft Teams and Google Chrome to deliver another pair of NSIS installers, one of which covertly installs RONINGLOADER, according to an Elastic Security Labs analysis. After loading a new dll to remove userland hooks and terminating anti-virus solutions, RONINGLOADER proceeds with batch script execution for User Account Control evasion and rogue DLL injection into the Windows binary 'regsvr32.exe' for further stealth ahead of the distribution of a modified Gh0st RAT payload.

Aside from allowing Windows Registry key configuration, clipboard data manipulation, command execution, and shell code injections, such updated Gh0st RAT malware also enables keystroke and foreground window title logging. Such findings follow a Palo Alto Networks Unit 42 report detailing a pair of linked Gh0st RAT attack campaigns against Chinese-speaking users.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds