Dragon Breath
Dragon Breath, also tracked as APT-Q-27 and Golden Eye Dog, is a financially motivated threat actor. Elastic Security Labs described it as targeting the gambling sector using SERP poisoning, social engineering, and DDoS attacks. More recent reporting attributed to Dragon Breath documents malware delivery through trojanized MSI and NSIS installers masquerading as legitimate software such as Google Chrome and Microsoft Teams, with campaigns primarily targeting Chinese-speaking users. In the reported 2025 activity, Dragon Breath used a custom multi-stage loader named RoningLoader to deliver a modified gh0st RAT. The intrusion chain included multiple defense-evasion and anti-security techniques: loading a fresh copy of ntdll.dll and resolving APIs dynamically to reduce userland hook visibility; privilege escalation via runas; use of a legitimately signed kernel driver, ollama.sys, to terminate security processes; abuse of Protected Process Light through ClipUp.exe to corrupt Microsoft Defender’s MsMpEng.exe; phantom DLL side-loading via Wow64Log.dll; thread-pool-based remote execution; and deployment of an unsigned WDAC policy to block Chinese antivirus products including Qihoo 360 and Huorong. The malware also modified firewall settings, disabled UAC, created services, and used watchdog batch scripts for persistence. The final payload was reported as a modified version of the open-source gh0st RAT, linked by Elastic to prior Dragon Breath reporting by Sophos and QianXin. Reported capabilities included encrypted raw TCP C2 communications, beaconing, command execution, file download and execution, event log clearing, process injection, keylogging, clipboard logging and hijacking, active-window logging, and collection of host, OS, CPU, privilege, uptime, antivirus, Telegram, and clipboard-related metadata. Known aliases and associated names directly mentioned in the content include APT-Q-27 and Golden Eye Dog.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they target
Geographies tied to known operations.
- 🇨🇳 China
Tradecraft
27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
4 malware families attributed to this actor across reporting.
Observables
33 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a threat actor known for using DLL sideloading, specifically a double-sideloading attack.
Actor targeting primarily Chinese-speaking users using trojanized installers and a multi-stage loader (RONINGLOADER) to deploy a modified Gh0st RAT.
Dragon Breath (APT-Q-27, Golden Eye Dog) is a financially motivated group targeting the gambling sector using multi-stage loaders, SERP poisoning, social engineering, and DDoS attacks.
Conducting malware delivery campaigns against Chinese-speaking users using trojanized installers, a custom loader named RoningLoader, and a modified gh0st RAT, with strong emphasis on defense evasion and disabling Chinese-market security products and Microsoft Defender.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.