Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors DragonBreath

Also known as: Golden Eye Dog, APT-Q-27,, APT-Q-27, REF9403, tracked as, the Komodo monitor, the Dragon Queen, Synaptics worm, GoldenEyeDog, Dragon Breath, Mustang Panda, REF8747, Stately Tarurus

Description

DragonBreath is a sophisticated adversary that blends low‑profile Windows system tricks with advanced malware engineering. Their toolkit hinges on DLL side‑loading via a double‑clean app technique, signed driver implants to both persist and suppress Microsoft Defender protection, and an elaborate chain of trojanized NSIS installers masquerading as legitimate software such as Google Chrome or Microsoft Teams. These deployment vectors feed into multi‑stage loaders—most notably RONINGLOADER—which in turn drop a customized gh0st RAT variant for reconnaissance, data exfiltration and remote control. The actor’s campaigns emphasize stealth: they deploy thread‑pool injections, Protected Process Light (PPL) abuse, custom WDAC policy manipulation, and obfuscated code with dynamic API resolution to evade detection by both Western anti‑malware and Chinese EDR products. They also sidestep virtual machine checks, encrypt outbound traffic via proprietary symmetric algorithms, and use the Windows BITS service or remote WebDAV uploads for covert command and control. DragonBreath’s malware families include SADBRIDGE loaders and GOSAR backdoors in specific operations targeting Chinese‑speaking victims. In addition to the technical depth of their toolset, the group frequently purchases or registers malicious domain names and hosts payloads on Alibaba Cloud Object Storage Service (OSS) and public VPS resources to enhance survivability and anonymity. These tactics are employed across a wide range of industries—financial services, gaming, telecommunications, utilities, manufacturing—illustrating the actor’s broad profit‑driven agenda while leveraging opportunistic weaknesses in common Windows distributions.

Goals & Targeting

Targeted Sectors

Financial services
Government
Defense
Gaming
Retail
Telecommunications
Information technology
Utilities
Non profit
Manufacturing

Targeted Countries / Regions

KP
CN
TW
UA
KZ
PK
US
JP
BY
SY
AU
RU
AZ
IN
BR

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

DragonBreath, also known as APT‑Q‑27, is a financially motivated threat actor that targets diverse sectors across numerous countries, with a particular focus on Chinese‑speaking populations and online gambling operators. The group launches multi‑stage campaigns using DLL side‑loading, signed driver deployment, and trojanized NSIS/MSI installers to achieve persistence while disabling Windows Defender via PPL abuse. By leveraging custom loaders like RONINGLOADER and BITS‑based C2 channels it maintains stealthy command and control, exfiltrating data through encrypted channels over the same traffic streams.

Goals & Targeting

DragonBreath’s primary objective is financial gain through direct theft, credential harvesting, and the monetization of accessed data. By targeting online gambling operators and various corporate sectors, they can exploit high-value transaction channels or sensitive proprietary information such as trade secrets or customer databases. The actor’s geographic reach (South Korea, China, Taiwan, Ukraine, Kazakhstan, Pakistan, United States, Japan, Belarus, Syria, Australia, Russia, Azerbaijan, India, Brazil) reflects a strategy focused on low‑cost, high‑return targets rather than purely political motives. Their methodology—spear‑phishing with disguised installers, social engineering of Chinese‑speaking users, and DDoS‑style disruptions—further serves to undermine trust in affected services while providing the actor leverage over victims."

Enhanced Description

Key Capabilities

  • DLL side‑loading via double‑clean app technique
  • Signed driver deployment for persistence and disabling Windows Defender
  • Thread‑pool injection for stealthy execution
  • Protected Process Light (PPL) abuse to evade EDR and Defender
  • Custom WDAC policy manipulation
  • Trojanized NSIS installers masquerading as legitimate applications
  • Multi‑stage loader delivery chain (RONINGLOADER, SADBRIDGE, GOSAR backdoor)
  • Malicious MSI installers signed with self‑signed certificates
  • Persistence via scheduled tasks and registry Run key entries
  • Windows Command Shell used to download from Alibaba Cloud OSS
  • Obfuscated code with dynamic API resolution and DLL side‑loading
  • Evade virtual machine/analysis checks
  • Custom symmetric encryption for traffic exfiltration/C2
  • Exfiltration over same channel as command & control
  • BITS‑based stealthy C2 communications

MITRE ATT&CK Tactics

Defense Evasion
Persistence
Resource Development
Initial Access
Execution
Collection
Command and Control
Exfiltration

ATT&CK Techniques

T1053.005
T1056.001
T1068
T1106
T1119
T1140
T1204.002
T1497.001
T1553.002
T1573.001
T1574.001
T1574.002
T1574.005
T1574.006
T1574.007
T1574.008
T1574.009
T1574.010
T1574.011
T1574.013
T1574.014
T1583.001
T1583.003
T1585.003
T1587.002
T1608.001
T1020
T1027.007
T1027.009
T1041
T1059.003
T1189
T1078
T1095

Software / Tooling

gh0st RAT
RonIngLoader
SADBRIDGE
GOSAR backdoor
FatalRAT
PlugX
BITS-based Windows backdoor

Campaigns & Victims

DragonBreath conducts opportunistic, high‑frequency campaigns that often surface as short cycles spanning days to a few weeks. Their attack footprint typically begins with social engineering or drive‑by compromise via counterfeit popular applications, followed by the deployment of tampered NSIS/MSI installers. Persistence is achieved through scheduled tasks and registry run keys, while evasive techniques (DLL side‑loading, PPL abuse, WDAC manipulation) enable them to remain hidden from conventional endpoint detection. Victims historically include gambling operators, fintech entities, and defense contractors in East Asia and the US, with occasional infiltration of global telecom and utility providers. Notable operations such as “Operation Dragon Breath” exposed their use of double‑clean DLL sideloading combined with custom symmetric encryption for command and control.","ioc_patterns":["DLL sideloading via double-clean app technique","Signed driver deployment for persistence and disabling Defender","PPL abuse to tamper with Defender binary","Trojanized NSIS installers disguised as legitimate applications","Malicious domain acquisition","VPS hosting for malware/C&C","Malicious MSI installers on Alibaba Cloud OSS","Self‑signed certificates signing MSI files","DLL side-loading hijacking","BITS-based C2 communications"],"recommended_actions":["Implement strict policy controls for DLL loading and monitor dll sideloading activities","Whitelist signed drivers and block unauthorized driver installation","Use WDAC or Windows Defender ExploitGuard to enforce trusted binaries","Deploy application whitelisting and integrity checking to detect trojanized installers","Maintain updated signatures for known malicious NSIS/MSI packages","Block known malicious domains/IPs associated with DragonBreath","Monitor scheduled task creation and registry Run key modifications","Enable detection of thread‑pool injection, DLL side-loading, dynamic API resolution in EDR","Inspect outbound traffic for BITS usage as potential C2 channel","Enhance Defender monitoring for PPL abuse and signed driver loading"],"suggested_tags":["DLL Sideloading","Signed Driver Deployment","PPL Abuse","Trojanized Installer","gh0st RAT","APT","Malware","Chinese State‑Sponsored","DragonBreath","Mustang Panda","REF8747","PlugX","FatalRAT","BITS C2","SADBRIDGE","GOSAR backdoor"],"confidence_assessment":"The intelligence on DragonBreath is drawn from multiple reputable sources, including industry blogs, vendor research, and publicly available malware databases. While the core capabilities—DLL sideloading, signed driver deployment, and multi‑stage loaders—are well documented, certain details such as exact persistence vectors or full command‑and‑control pathways remain partially speculative due to limited attribution evidence in some reports. Consequently, confidence is high for known TTPs and tool associations but moderate regarding precise operational footprints and future campaign evolution.","sources":["https://thehackernews.com/2023/05/dragon-breath-apt-group-using-double.html","https://www.cisa.gov/eviction-strategies-tool/info-attack/T1574.001","https://malpedia.caad.fkie.fraunhofer.de/actor/dragonbreath","https://www.sophos.com/en-us/blog/doubled-dll-sideloading-dragon-breath","https://telsy.com/en/new-exploit-chain","https://ti.qianxin.com/blog/articles/operation-dragon-breath-%28apt-q-27%29-dimensionality-reduction-blow-to-the-gambling-industry/","https://www.elastic.co/security-labs/topics/malware-analysis"]}

ATT&CK Techniques

Defense impairment
1 technique
Initial Access
1 technique
Privilege Escalation
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.elastic.co — Cited by web research for: REF9403
  2. attack.mitre.org — Cited by web research for: Mustang Panda
  3. www.welivesecurity.com — Cited by web research for: T1583.001
  4. www.elastic.co — Cited by web research for: Telegram
  5. www.sophos.com — Cited by web research for: curl

Intel Summary

39

Techniques

47

Tools

0

Campaigns

40

IOCs

0

Observed Data

11

Tactics

Tags

APT
Backdoor / C2
DDoS
espionage
finance-sector
online-gambling
social-engineering
china-related

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
North Korea (KP)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.