DragonBreath is a threat group targeting Chinese-speaking online gambling users with trojanized installers and Gh0st RAT.
Analyst brief
DragonBreath (also known as Golden Eye Dog, APT-Q-27) targets Chinese-speaking users involved in online gambling. The group's key TTPs include SERP poisoning, social engineering, DDoS attacks, and the use of trojanized NSIS installers to deliver the RONINGLOADER, which subsequently deploys a modified Gh0st RAT via complex process-injection and DLL sideloading. Defenders should heighten monitoring for watering hole websites, scrutinize unusual NSIS installers, and track network indicators linked to Gh0st RAT activity.
DragonBreath
Golden Eye DogAPT-Q-27,
unknown
Golden Eye Dog targets Chinese-speaking users engaged in online gambling, employing techniques such as SERP poisoning, social engineering, and DDoS attacks. The group utilizes trojanized NSIS installers to deliver RONINGLOADER, which executes complex process-injection workflows and deploys a modified Gh0st RAT for espionage. Their operations have included DLL sideloading and the use of watering hole websites to implant Trojans. The group is noted for its high anti-detection capabilities and has been associated with various malware development languages.