External Publication
Visit Post

RoningLoader malware campaign hides behind fake Chrome and Teams installers to disable security tools

VPN Central [Unofficial] April 9, 2026
Source
RoningLoader is a stealthy malware loader tied to DragonBreath, also tracked as APT-Q-27. It targets Chinese-speaking users and spreads through trojanized NSIS installers that pretend to be trusted software such as Google Chrome and Microsoft Teams. Elastic Security Labs documented the campaign in November 2025, while AttackIQ published a fresh adversary emulation update on April […] The post RoningLoader malware campaign hides behind fake Chrome and Teams installers to disable security tools appeared first on VPN Central.

Discussion in the ATmosphere

Loading comments...