DragonBreath
Aliases: Golden Eye Dog, APT-Q-27,
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:23:01
Targeted industries: media-and-entertainment retail-and-hospitality
Targeted regions: country_code:cn
Context
Golden Eye Dog targets Chinese-speaking users engaged in online gambling, employing techniques such as SERP poisoning, social engineering, and DDoS attacks. The group utilizes trojanized NSIS installers to deliver RONINGLOADER, which executes complex process-injection workflows and deploys a modified Gh0st RAT for espionage. Their operations have included DLL sideloading and the use of watering hole websites to implant Trojans. The group is noted for its high anti-detection capabilities and has been associated with various malware development languages.
Reports & references
- sophos.com — Doubled Dll Sideloading Dragon Breath (report)