
Dragon Breath Malware: How RONINGLOADER Disables Security Tools to Deploy Gh0st RAT
The threat actor known as Dragon Breath has been noted for using a multi-stage loader called RONINGLOADER to deploy a modified variant of the remote access trojan named Gh0st RAT. This campaign primarily targets Chinese-speaking users and utilizes trojanized NSIS




