DragonBreath, also tracked as APT-Q-27 and Golden Eye Dog, is a financially motivated Chinese-nexus threat actor active since at least 2020. It has primarily targeted Chinese-speaking users and organizations in the online gaming and gambling sectors across China, Taiwan, Hong Kong, Japan, Singapore, and the Philippines. The group has used search-engine poisoning, social engineering, and trojanized installers impersonating legitimate software and services to deliver malware. DragonBreath is associated with modified variants of Gh0st RAT and with multi-stage loader families including RoningLoader. Its malware provides remote command execution, payload download and execution, host and security-product discovery, clipboard access and manipulation, event-log clearing, process injection, and configurable persistence. Reported implants also collect keystrokes, clipboard contents, and active-window information. The actor employs extensive defense-evasion and endpoint-security-disabling techniques. These include DLL side-loading, in-memory execution, thread-pool-based process injection, UAC disabling, firewall manipulation, malicious Windows Defender Application Control policies, and abuse of Protected Process Light functionality to impair Microsoft Defender. DragonBreath has also deployed legitimately signed malicious kernel drivers to terminate antivirus and EDR processes, including protected processes, modify process command-line telemetry in memory, and conceal processes. Campaigns have used code-signing certificates associated with Chinese shell companies and malware-signing infrastructure. DragonBreath activity has additionally been linked to DDoS attacks against gambling-sector targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
30 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
40 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Assessed with medium confidence as a nation-state-adjacent campaign using dual code-signing trust chains, a Telegram-based reverse shell, browser-based host fingerprinting, and high-frequency scheduled-task persistence. The actor is assessed to have sourced disposable signing capabilities through commercial criminal services.
Referenced as a threat actor known for using DLL sideloading, specifically a double-sideloading attack.
Associated in this report with a coordinated kernel-level offensive toolkit: EDR termination and command-line telemetry spoofing via dragoncore_k.sys, process hiding, YDArk rootkit capabilities, and Cobalt Strike C2 delivered through a trojanized Telegram installer.
Conducts targeted intrusion campaigns using trojanized LetsVPN and Telegram installers, signed loaders, Cobalt Strike, kernel drivers, and PPL/EDR-bypass techniques. The group is assessed as using Zhengzhou 403 as a signing and infrastructure vehicle.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.