Friday, September 11, 2026

RONINGLOADER Uses Signed Drivers to Disable Microsoft Defender and Bypass EDR

Elastic Security Labs has uncovered a sophisticated campaign deploying a newly identified loader, dubbed RONINGLOADER, that weaponizes legitimately signed kernel drivers to systematically disable Microsoft Defender and evade endpoint detection and response (EDR) tools.

Attributed to the Dragon Breath APT group (APT-Q-27), this campaign demonstrates a significant evolution in attack sophistication, primarily targeting Chinese-speaking users through trojanized installers masquerading as legitimate software, including Google Chrome and Microsoft Teams.

The malware employs an intricate multi-stage delivery mechanism leveraging Protected Process Light (PPL) abuse, custom Windows Defender Application Control (WDAC) policies, and kernel-mode drivers to neutralize popular endpoint security solutions in the Chinese market.

This campaign marks a clear advancement from earlier Dragon Breath activities documented between 2022 and 2023, showcasing the threat actor’s growing technical capabilities and adaptability.

The discovery of RONINGLOADER followed August 2025 research detailing methods for abusing PPL to turn off endpoint security tooling.

Elastic Security Labs developed behavioral detection rules in response and subsequently identified active exploitation in the wild through telemetry analysis.

The initial infection vector utilizes the Nullsoft Scriptable Install System (NSIS), a legitimate but frequently abused installer framework. The malicious installers employ a nested NSIS architecture, bundling both legitimate software alongside malicious payloads to maintain deception during execution.

Multi-Stage Evasion Architecture

The attack chain operates through four distinct stages. Stage One comprises the initial trojanized installer, which drops a malicious DLL and encrypted shellcode.

Files dropped on disk.
Files dropped on disk.

Upon execution with elevated privileges, Stage Two performs reconnaissance to identify running security processes and initiates systematic termination of antivirus products including Microsoft Defender, Kingsoft Internet Security, Tencent PC Manager, Qihoo 360 Total Security, and Huorong Security.

RONINGLOADER leverages a signed kernel driver named ollama.sys, issued by Kunming Wuqi E-commerce Co., Ltd. with a certificate valid through February 2026, to terminate security processes from kernel mode.

When invoked, this function reads the contents of the tp.png file from disk, then decrypts this data using a simple algorithm involving both a Right Rotate (ROR) and an XOR operation.

XOR decryption routine.
XOR decryption routine.

The driver handles IOCTL requests to kill processes by PID, bypassing user-mode process protections. Remarkably, Elastic researchers discovered 71 additional signed binaries using the same certificate, suggesting potential certificate compromise or deliberate distribution for malicious purposes.

Digital signature of the driver.
Digital signature of the driver.

The malware implements redundant termination techniques across multiple stages. Beyond driver-based process killing, RONINGLOADER deploys phantom DLL side-loading, thread pool injection techniques, and firewall manipulation to isolate security software from network communication.

Most notably, it implements a PPL abuse technique targeting Microsoft Defender specifically, leveraging ClipUp.exe to overwrite the MsMpEng.exe binary with junk data, effectively disabling Windows Defender even after system restart.

Custom unsigned WDAC policies are deployed to explicitly block execution of Qihoo 360 Total Security (360rp.exe, 360sd.exe) and Huorong Security (ARPProte.exe) processes, preventing their operation entirely. This approach demonstrates strategic targeting of security solutions prevalent in the Chinese threat landscape.

Final Payload and Persistence

Stage Three and Four orchestrate injection of the final payload a modified version of the open-source gh0st RAT into trusted system processes including TrustedInstaller.exe or elevation_service.exe.

The malware then scans a list of running processes for specific antivirus solutions. It checks against a hardcoded list of process names and sets a corresponding boolean flag to “True” if any are found.

Scans for specific processes.
Scans for specific processes.

The implant maintains C2 communication over encrypted TCP channels and implements keystroke logging, clipboard hijacking, and cryptocurrency wallet monitoring capabilities.

It tracks explicitly MetaMask wallet interactions and Telegram application usage, suggesting victims may include cryptocurrency and finance-focused targets.

The discovery of RONINGLOADER represents a concerning escalation in APT capabilities, particularly regarding abuse of legitimate Windows features and signed drivers for security product neutralization. Organizations operating in Chinese markets face heightened risk from this evolving threat.

Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

OpenMatter Network Realigns Leadership Team to Accelerate Global Commercial Growth

Melbourne, Florida, September 10th, 2026, CyberNewswire With its Verification Architecture...

Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft

Nearly one in 10 internet-exposed LiteLLM AI gateways accepted...

Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone

Skullcandy Dime 3 wireless earbuds have a serious vulnerability...

Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly

Threat actors are increasingly exploiting Active Directory replication mechanisms...

Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers

Threat actors are exploiting anticipation around Grand Theft Auto...

Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds

A recently disclosed integer-underflow vulnerability in Apple’s modern Mach-O...

Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root

Palo Alto Networks has announced a high-severity buffer overflow...

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

A phishing campaign that moves the credential-harvesting page out...

Related Articles

Recent News