Attacks with the multi-stage RONINGLOADER payload have been launched by the advanced persistent threat operation Dragon Breath to facilitate updated Gh0st RAT malware deployment as part of a campaign mostly aimed at Chinese speakers, The Hacker News reports.Dragon Breath, also known as Golden Eye and APT-Q-27, leveraged trojanized NSIS installers spoofing Microsoft Teams and Google Chrome to deliver another pair of NSIS installers, one of which covertly installs RONINGLOADER, according to an Elastic Security Labs analysis. After loading a new dll to remove userland hooks and terminating anti-virus solutions, RONINGLOADER proceeds with batch script execution for User Account Control evasion and rogue DLL injection into the Windows binary 'regsvr32.exe' for further stealth ahead of the distribution of a modified Gh0st RAT payload.Aside from allowing Windows Registry key configuration, clipboard data manipulation, command execution, and shell code injections, such updated Gh0st RAT malware also enables keystroke and foreground window title logging. Such findings follow a Palo Alto Networks Unit 42 report detailing a pair of linked Gh0st RAT attack campaigns against Chinese-speaking users.
Malware, Threat Intelligence
Novel RONINGLOADER loader leveraged in Dragon Breath APT attacks
(Adobe Stock)
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
