APT-Q-27, also known as GoldenEyeDog and Dragon Breath, is a Chinese-nexus threat actor active since at least 2022 and associated with long-running campaigns against cryptocurrency- and gambling-related targets, including Web3 organizations and customer support teams. The group is known for combining social engineering with multi-stage malware delivery, including lures delivered through live support chats, fake recruitment workflows, trojanized software, and signed malicious executables. Reported operations show a consistent emphasis on stealth, persistence, and credential access, with malware families and tooling that include custom backdoors, information stealers, plugin-based remote access implants, and hidden VNC capability. APT-Q-27 commonly uses staged infection chains that rely on trusted or legitimate-seeming delivery mechanisms such as code-signed binaries, ClickOnce deployment, cloud-hosted payload retrieval, and DLL sideloading. Its malware has been observed performing anti-analysis and anti-debugging checks, decrypting and loading payloads directly in memory, dynamically resolving APIs, and maintaining persistence through Windows services, registry autoruns, and scheduled tasks. Documented runtime artifacts and malware lineage link multiple campaigns under the APT-Q-27 / GoldenEyeDog / Dragon Breath cluster. Observed capabilities include credential theft, browser session theft, keylogging, clipboard and wallet-focused theft, command execution, file browsing, proxying, persistence, and covert remote desktop control through hidden VNC. In cryptocurrency intrusions, the actor has been linked to theft of private keys, browser data, cloud and source-control tokens, and other sensitive secrets, enabling rapid asset theft across multiple chains. Recent activity indicates a shift from reliance on trojanized software and watering-hole style distribution toward direct social-engineering engagement with support personnel in Web3 environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
53 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
286 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in related content as a Web3-targeting threat group using fake screenshot links to install a persistent backdoor.
Linked to the long-running sims-4-updater malware distribution campaign, using a custom PE64 backdoor, EV code-signing abuse, live C2 infrastructure, and dead-drop resolvers via rentry.co/rentry.org/GitHub gist. The group is also described as historically targeting gambling operators and Chinese-speaking gambling players in Southeast Asia, and was tied to a January 2026 corporate intrusion in Vietnam.
Conducting social-engineering-based intrusions against Web3 customer support teams by posing as customers in support chats and delivering a multi-stage backdoor via fake screenshot links. The group has been active since at least 2022 and has a history of targeting the gambling and cryptocurrency sectors.
A sophisticated multi-stage intrusion linked by infrastructure and tradecraft similarities to prior APT-Q-27 activity. The campaign used a phishing-delivered .pif dropper, digitally signed malware, DLL sideloading, persistence via registry and Windows services, in-memory payload execution, and a modular plugin-based backdoor architecture.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.