216.73.217.22

Operation Dragon Breath (APT-Q-27): Dimensional Reduction Attack Against the Gambling Industry

· Published 05/11/2025 12:36 · Modified 05/11/2025 21:49

Export JSON

Essential information

Published
05/11/2025 12:36
Modified
05/11/2025 21:49
Tags
2025-11-05 chinese communities gambling industry ghost golden eye dog miuuti group msi installer southeast asia telegram watering hole
Related entities
1 intrusion sets (apt), 16 techniques (mitre), 1 others

Description

A threat group known as (APT-Q-27) has been targeting individuals involved in gambling and related activities in , as well as overseas . The group's operations include remote control, cryptocurrency mining, DDoS attacks, and traffic-related activities. Their malware samples are primarily distributed through groups, with strong anti-detection capabilities and highly targeted lures. The article describes new activities by the group, including the use of modified MSI installers for popular messaging apps like . The group has evolved its tactics since previous reports, making their operations more covert and difficult to detect. The analysis reveals the group's use of various programming languages and sophisticated techniques, suggesting it may be part of a larger, more advanced organization called .

External references