Also known as: Golden Eye Dog, APT-Q-27,, APT-Q-27, REF9403, tracked as, the Komodo monitor, the Dragon Queen, Synaptics worm, GoldenEyeDog, Dragon Breath, Mustang Panda, REF8747, Stately Tarurus
DragonBreath is a sophisticated adversary that blends low‑profile Windows system tricks with advanced malware engineering. Their toolkit hinges on DLL side‑loading via a double‑clean app technique, signed driver implants to both persist and suppress Microsoft Defender protection, and an elaborate chain of trojanized NSIS installers masquerading as legitimate software such as Google Chrome or Microsoft Teams. These deployment vectors feed into multi‑stage loaders—most notably RONINGLOADER—which in turn drop a customized gh0st RAT variant for reconnaissance, data exfiltration and remote control. The actor’s campaigns emphasize stealth: they deploy thread‑pool injections, Protected Process Light (PPL) abuse, custom WDAC policy manipulation, and obfuscated code with dynamic API resolution to evade detection by both Western anti‑malware and Chinese EDR products. They also sidestep virtual machine checks, encrypt outbound traffic via proprietary symmetric algorithms, and use the Windows BITS service or remote WebDAV uploads for covert command and control. DragonBreath’s malware families include SADBRIDGE loaders and GOSAR backdoors in specific operations targeting Chinese‑speaking victims. In addition to the technical depth of their toolset, the group frequently purchases or registers malicious domain names and hosts payloads on Alibaba Cloud Object Storage Service (OSS) and public VPS resources to enhance survivability and anonymity. These tactics are employed across a wide range of industries—financial services, gaming, telecommunications, utilities, manufacturing—illustrating the actor’s broad profit‑driven agenda while leveraging opportunistic weaknesses in common Windows distributions.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
DragonBreath, also known as APT‑Q‑27, is a financially motivated threat actor that targets diverse sectors across numerous countries, with a particular focus on Chinese‑speaking populations and online gambling operators. The group launches multi‑stage campaigns using DLL side‑loading, signed driver deployment, and trojanized NSIS/MSI installers to achieve persistence while disabling Windows Defender via PPL abuse. By leveraging custom loaders like RONINGLOADER and BITS‑based C2 channels it maintains stealthy command and control, exfiltrating data through encrypted channels over the same traffic streams.
Goals & Targeting
DragonBreath’s primary objective is financial gain through direct theft, credential harvesting, and the monetization of accessed data. By targeting online gambling operators and various corporate sectors, they can exploit high-value transaction channels or sensitive proprietary information such as trade secrets or customer databases. The actor’s geographic reach (South Korea, China, Taiwan, Ukraine, Kazakhstan, Pakistan, United States, Japan, Belarus, Syria, Australia, Russia, Azerbaijan, India, Brazil) reflects a strategy focused on low‑cost, high‑return targets rather than purely political motives. Their methodology—spear‑phishing with disguised installers, social engineering of Chinese‑speaking users, and DDoS‑style disruptions—further serves to undermine trust in affected services while providing the actor leverage over victims."
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
DragonBreath conducts opportunistic, high‑frequency campaigns that often surface as short cycles spanning days to a few weeks. Their attack footprint typically begins with social engineering or drive‑by compromise via counterfeit popular applications, followed by the deployment of tampered NSIS/MSI installers. Persistence is achieved through scheduled tasks and registry run keys, while evasive techniques (DLL side‑loading, PPL abuse, WDAC manipulation) enable them to remain hidden from conventional endpoint detection. Victims historically include gambling operators, fintech entities, and defense contractors in East Asia and the US, with occasional infiltration of global telecom and utility providers. Notable operations such as “Operation Dragon Breath” exposed their use of double‑clean DLL sideloading combined with custom symmetric encryption for command and control.","ioc_patterns":["DLL sideloading via double-clean app technique","Signed driver deployment for persistence and disabling Defender","PPL abuse to tamper with Defender binary","Trojanized NSIS installers disguised as legitimate applications","Malicious domain acquisition","VPS hosting for malware/C&C","Malicious MSI installers on Alibaba Cloud OSS","Self‑signed certificates signing MSI files","DLL side-loading hijacking","BITS-based C2 communications"],"recommended_actions":["Implement strict policy controls for DLL loading and monitor dll sideloading activities","Whitelist signed drivers and block unauthorized driver installation","Use WDAC or Windows Defender ExploitGuard to enforce trusted binaries","Deploy application whitelisting and integrity checking to detect trojanized installers","Maintain updated signatures for known malicious NSIS/MSI packages","Block known malicious domains/IPs associated with DragonBreath","Monitor scheduled task creation and registry Run key modifications","Enable detection of thread‑pool injection, DLL side-loading, dynamic API resolution in EDR","Inspect outbound traffic for BITS usage as potential C2 channel","Enhance Defender monitoring for PPL abuse and signed driver loading"],"suggested_tags":["DLL Sideloading","Signed Driver Deployment","PPL Abuse","Trojanized Installer","gh0st RAT","APT","Malware","Chinese State‑Sponsored","DragonBreath","Mustang Panda","REF8747","PlugX","FatalRAT","BITS C2","SADBRIDGE","GOSAR backdoor"],"confidence_assessment":"The intelligence on DragonBreath is drawn from multiple reputable sources, including industry blogs, vendor research, and publicly available malware databases. While the core capabilities—DLL sideloading, signed driver deployment, and multi‑stage loaders—are well documented, certain details such as exact persistence vectors or full command‑and‑control pathways remain partially speculative due to limited attribution evidence in some reports. Consequently, confidence is high for known TTPs and tool associations but moderate regarding precise operational footprints and future campaign evolution.","sources":["https://thehackernews.com/2023/05/dragon-breath-apt-group-using-double.html","https://www.cisa.gov/eviction-strategies-tool/info-attack/T1574.001","https://malpedia.caad.fkie.fraunhofer.de/actor/dragonbreath","https://www.sophos.com/en-us/blog/doubled-dll-sideloading-dragon-breath","https://telsy.com/en/new-exploit-chain","https://ti.qianxin.com/blog/articles/operation-dragon-breath-%28apt-q-27%29-dimensionality-reduction-blow-to-the-gambling-industry/","https://www.elastic.co/security-labs/topics/malware-analysis"]}
No campaigns linked yet.
No observed data linked yet.
39
Techniques
47
Tools
0
Campaigns
40
IOCs
0
Observed Data
11
Tactics