Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

RONINGLOADER Uses Signed Drivers to Disable Microsoft Defender and Bypass EDR

Elastic Security Labs has uncovered a sophisticated campaign deploying a newly identified loader, dubbed RONINGLOADER, that weaponizes legitimately signed kernel drivers to systematically disable Microsoft Defender and evade endpoint detection and…

Elastic Security Labs has uncovered a sophisticated campaign deploying a newly identified loader, dubbed RONINGLOADER, that weaponizes legitimately signed kernel drivers to systematically disable Microsoft Defender and evade endpoint detection and response (EDR) tools.Attributed to the Dragon Breath APT group (APT-Q-27), this campaign demonstrates a significant evolution in attack sophistication, primarily targeting Chinese-speaking users through trojanized installers masquerading as legitimate software, including Google Chrome and Microsoft Teams.The malware employs an intricate multi-stage delivery mechanism leveraging Protected Process Light (PPL) abuse, custom Windows Defender Application Control (WDAC) policies, and kernel-mode drivers to neutralize popular endpoint security solutions in the Chinese market.This campaign marks a clear advancement from earlier Dragon Breath activities documented between 2022 and 2023, showcasing the threat actor’s growing technical capabilities and adaptability.The discovery of RONINGLOADER followed August 2025 research detailing methods for abusing PPL to turn off endpoint security tooling.Elastic Security Labs developed behavioral detection rules in response and subsequently identified active exploitation in the wild through telemetry analysis.The initial infection vector utilizes the Nullsoft Scriptable Install System (NSIS), a legitimate but frequently abused installer framework. The malicious installers employ a nested NSIS architecture, bundling both legitimate software alongside malicious payloads to maintain deception during execution.Multi-Stage Evasion ArchitectureThe attack chain operates through four distinct stages. Stage One comprises the initial trojanized installer, which drops a malicious DLL and encrypted shellcode.Files dropped on disk.Upon execution with elevated privileges, Stage Two performs reconnaissance to identify running security processes and initiates systematic termination of antivirus products including Microsoft Defender, Kingsoft Internet Security, Tencent PC Manager, Qihoo 360 Total Security, and Huorong Security.RONINGLOADER leverages a signed kernel driver named ollama.sys, issued by Kunming Wuqi E-commerce Co., Ltd. with a certificate valid through February 2026, to terminate security processes from kernel mode.When invoked, this function reads the contents of the tp.png file from disk, then decrypts this data using a simple algorithm involving both a Right Rotate (ROR) and an XOR operation.XOR decryption routine.The driver handles IOCTL requests to kill processes by PID, bypassing user-mode process protections. Remarkably, Elastic researchers discovered 71 additional signed binaries using the same certificate, suggesting potential certificate compromise or deliberate distribution for malicious purposes.Digital signature of the driver.The malware implements redundant termination techniques across multiple stages. Beyond driver-based process killing, RONINGLOADER deploys phantom DLL side-loading, thread pool injection techniques, and firewall manipulation to isolate security software from network communication.Most notably, it implements a PPL abuse technique targeting Microsoft Defender specifically, leveraging ClipUp.exe to overwrite the MsMpEng.exe binary with junk data, effectively disabling Windows Defender even after system restart.Custom unsigned WDAC policies are deployed to explicitly block execution of Qihoo 360 Total Security (360rp.exe, 360sd.exe) and Huorong Security (ARPProte.exe) processes, preventing their operation entirely. This approach demonstrates strategic targeting of security solutions prevalent in the Chinese threat landscape.Final Payload and PersistenceStage Three and Four orchestrate injection of the final payload a modified version of the open-source gh0st RAT into trusted system processes including TrustedInstaller.exe or elevation_service.exe.The malware then scans a list of running processes for specific antivirus solutions. It checks against a hardcoded list of process names and sets a corresponding boolean flag to “True” if any are found.Scans for specific processes.The implant maintains C2 communication over encrypted TCP channels and implements keystroke logging, clipboard hijacking, and cryptocurrency wallet monitoring capabilities.It tracks explicitly MetaMask wallet interactions and Telegram application usage, suggesting victims may include cryptocurrency and finance-focused targets.The discovery of RONINGLOADER represents a concerning escalation in APT capabilities, particularly regarding abuse of legitimate Windows features and signed drivers for security product neutralization. Organizations operating in Chinese markets face heightened risk from this evolving threat.Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Based on reporting by GBHackers.

Advertisement
AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories