RoningLoader malware campaign hides behind fake Chrome and Teams installers to disable security tools
VPN Central [Unofficial]
April 9, 2026
RoningLoader is a stealthy malware loader tied to DragonBreath, also tracked as APT-Q-27. It targets Chinese-speaking users and spreads through trojanized NSIS installers that pretend to be trusted software such as Google Chrome and Microsoft Teams. Elastic Security Labs documented the campaign in November 2025, while AttackIQ published a fresh adversary emulation update on April […]
The post RoningLoader malware campaign hides behind fake Chrome and Teams installers to disable security tools appeared first on VPN Central.
Discussion in the ATmosphere