RONINGLOADER is a multi-stage Windows malware loader used by the China-linked financially motivated DragonBreath group, also tracked as APT-Q-27 and GoldenEyeDog. It has been distributed to primarily Chinese-speaking users in trojanized MSI and NSIS installers impersonating legitimate applications, including browser, collaboration, and VPN software. The loader executes later stages in memory, obtains or attempts administrative elevation, and deploys a modified Gh0st RAT payload.
RONINGLOADER employs a layered defense-evasion chain targeting Microsoft Defender and Chinese endpoint-security products, including Qihoo 360, Huorong, Kingsoft, and Tencent PC Manager. It enumerates security processes; manipulates firewall settings; disables UAC; uses phantom-DLL side-loading and thread-pool-based process injection; and abuses ClipUp Protected Process Light functionality to corrupt Microsoft Defender components. It also loads a signed malicious Windows kernel driver through temporary services and directs the driver to terminate security processes. The loader can install an unsigned WDAC policy to prevent selected antivirus products from executing and establishes persistence through malicious services and watchdog mechanisms.
The delivered modified Gh0st RAT communicates over encrypted raw TCP and supports remote command execution, payload download and execution, host and security-product discovery, process injection, event-log clearing, persistence configuration, keystroke logging, clipboard and active-window logging, and remotely configured clipboard hijacking. DragonBreath has targeted online gaming and gambling organizations and users in China and elsewhere in the Asia-Pacific region.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Elastic Security Labs documented a RONINGLOADER / Dragon Breath campaign using a LetsVPN-themed decoy, ollama.sys, and a modified gh0st RAT payload.
Elastic Security Labs documented a RONINGLOADER / Dragon Breath campaign using a LetsVPN-themed decoy, ollama.sys, and a modified gh0st RAT payload.
Elastic Security Labs detailed the adversary's use of a multi-stage loader codenamed RONINGLOADER to distribute a Gh0st RAT variant through NSIS installers masquerading as legitimate programs like Google Chrome and Microsoft Teams.
Through this report, we hope to raise awareness of new techniques this malware is starting to implement and to shine a light on a unique loader we are naming RoningLoader.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware injects shellcode into vssvc.exe and svchost.exe through Windows thread-pool tasks, and injects subsequent payloads into TrustedInstaller.exe or elevation_service.exe with VirtualAllocEx, WriteProcessMemory, and CreateRemoteThread.
The malware then injects code into regsvr32.exe — a native Windows utility — using CreateRemoteThread and LoadLibrary (T1055.001), pushing execution into high-privilege processes like TrustedInstaller.exe to conceal its activity further.
It grants itself the high integrity SeDebugPrivilege token before injecting into vssvc.exe.
RONINGLOADER writes ollama.sys to a temporary directory [and] creates a temporary service to load it.
letsvpn-3.12.3.exe is a LetsVPN-branded payload, and tsetup-x64.5.13.1.exe is described as a trojanized Telegram Desktop installer.
Trojanized NSIS installers masquerade as legitimate software such as Google Chrome and Microsoft Teams.
The malware injects shellcode into vssvc.exe and svchost.exe through Windows thread-pool tasks, and injects subsequent payloads into TrustedInstaller.exe or elevation_service.exe with VirtualAllocEx, WriteProcessMemory, and CreateRemoteThread.
The malware then injects code into regsvr32.exe — a native Windows utility — using CreateRemoteThread and LoadLibrary (T1055.001), pushing execution into high-privilege processes like TrustedInstaller.exe to conceal its activity further.
The scripts modify EnableLUA, while the final implant uses registry keys for persistence, configuration, telemetry tags, logger control, and clipboard-hijacker configuration.
The malware writes an unsigned WDAC policy into CiPolicies\Active that denies specified Qihoo 360 and Huorong executables.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RONINGLOADER is a malware loader that deploys the malicious ollama.sys kernel driver via a temporary service and instructs it to terminate targeted antivirus processes. The temporary service is deleted after the termination request.
A multi-stage loader used to distribute a Gh0st RAT variant via trojanized NSIS installers masquerading as legitimate software.
A Dragon Breath/APT-Q-27 multi-stage loader campaign using trojanized installers and benign decoy applications. It deploys ollama.sys for EDR/AV termination and subsequently delivers a modified gh0st RAT.
A multi-stage malware loader delivered via trojanized NSIS installers. It uses DLL side-loading, in-memory shellcode execution, code injection, privilege escalation, UAC disabling, and a signed kernel driver to disable security tools before deploying a final payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.