⤷ Title: Dragon Breath APT Deploys RoningLoader, Using Kernel Driver and PPL Abuse to Disable Windows Defender
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:05:28 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Defense Bypass #Dragon Breath #Gh0st RAT #Kernel Driver #PPL Abuse #Protected Process Light #RoningLoader
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:05:28 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Defense Bypass #Dragon Breath #Gh0st RAT #Kernel Driver #PPL Abuse #Protected Process Light #RoningLoader
Daily CyberSecurity
Dragon Breath APT Deploys RoningLoader, Using Kernel Driver and PPL Abuse to Disable Windows Defender
Elastic exposed Dragon Breath APT's new RoningLoader malware. It uses PPL abuse and a signed kernel driver (ollama.sys) to disable Windows Defender and inject a modified gh0st RAT for espionage.