DragonBreath
· Published 21/12/2025 18:51 · Modified 21/12/2025 18:51
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 21/12/2025 18:51
- Modified
- 21/12/2025 18:51
- Updated at
- 21/12/2025 18:51
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 1 reports, 21 attack patterns (mitre), 3 malware, 2 sectors, 1 countries, 14 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (1)
-
21 MITREs 4 Malwares 14 Observables 1 APTPublished 19/11/2025 08:54 · Modified 19/11/2025 09:44
Attack patterns (MITRE) (21)
-
T1115 usesClipboard Data
-
T1562.004 usesDisable or Modify System Firewall
-
T1036.005 usesMatch Legitimate Resource Name or Location
-
T1553.006 usesCode Signing Policy Modification
-
T1548.002 usesBypass User Account Control
-
T1543.003 usesWindows Service
-
T1055 usesProcess Injection
-
T1082 usesSystem Information Discovery
-
T1057 usesProcess Discovery
-
T1574.002 uses
-
T1562.001 usesDisable or Modify Tools
-
T1112 usesModify Registry
-
T1095 usesNon-Application Layer Protocol
-
T1070.001 usesClear Windows Event Logs
-
T1059.003 usesWindows Command Shell
-
T1134 usesAccess Token Manipulation
-
T1573.001 usesSymmetric Cryptography
-
T1056.001 usesKeylogging
-
T1569.002 usesService Execution
-
T1518.001 usesSecurity Software Discovery
-
T1033 usesSystem Owner/User Discovery
Malware (3)
-
RONINGLOADER usesFamilyPublished 19/11/2025 08:54 · Modified 19/11/2025 08:54
-
Mydoor usesFamilyPublished 17/04/2026 23:18 · Modified 17/04/2026 23:18
-
gh0st RAT - S0032 usesFamilyPublished 17/04/2026 23:18 · Modified 17/04/2026 23:18
Sectors (2)
- Government targets
- Technology targets
Countries (1)
- China targets
Indicators (14)
-
qaqkongtiao.comindicates -
395f835731d25803a791db984062dd5cfdcade6f95cc5d0f68d359af32f6258dindicates -
c65170be2bf4f0bd71b9044592c063eaa82f3d43fcbd8a81e30a959bcaad8ae5indicates -
96f401b80d3319f8285fa2bb7f0d66ca9055d349c044b78c27e339bcfb07cdf0indicates -
4d5beb8efd4ade583c8ff730609f142550e8ed14c251bae1097c35a756ed39e6indicates -
33b494eaaa6d7ed75eec74f8c8c866b6c42f59ca72b8517b3d4752c3313e617cindicates -
2515b546125d20013237aeadec5873e6438ada611347035358059a77a32c54f5indicates -
82794015e2b40cc6e02d3c1d50241465c0cf2c2e4f0a7a2a8f880edaee203724indicates -
fd4dd9904549c6655465331921a28330ad2b9ff1c99eb993edf2252001f1d107indicates -
1613a913d0384cbb958e9a8d6b00fffaf77c27d348ebc7886d6c563a6f22f2b7indicates -
1c1528b546aa29be6614707cbe408cb4b46e8ed05bf3fe6b388b9f22a4ee37e2indicates -
fc63f5dfc93f2358f4cba18cbdf99578fff5dac4cdd2de193a21f6041a0e01bcindicates -
da2c58308e860e57df4c46465fd1cfc68d41e8699b4871e9a9be3c434283d50bindicates -
3dd470e85fe77cd847ca59d1d08ec8ccebe9bd73fd2cf074c29d87ca2fd24e33indicates