RONINGLOADER Exploits Signed Drivers to Evade Security Tools

15 Nov 2025

RONINGLOADER, a sophisticated multi-stage loader, has been detected leveraging signed drivers to disable security software and evade Endpoint Detection and Response (EDR) tools. This new threat primarily targets users in China, deploying a modified gh0stRAT through trojanized installers.

Installation and Execution

The malicious software disguises itself as legitimate applications like Chrome and Teams through trojanized NSIS installers. Once installed, it establishes a directory at C:\Program Files\Snieoatwtregoable\ containing critical components such as Snieoatwtregoable.dll and an encrypted file named tp.png. The DLL decrypts this file using a combination of XOR and a rotate-right operation.

Security Evasion Techniques

In a calculated move, RONINGLOADER loads new system libraries to bypass existing security protocols and elevate its privileges using the 'runas' command. It further scans for several security products including Microsoft Defender, Kingsoft Internet Security, and Qihoo 360 Total Security.

Utilizing the signed driver, ollama.sys, registered by Kunming Wuqi E-commerce Co., Ltd., the malware effectively terminates security processes through kernel-level API access. Notably, RONINGLOADER creates a temporary service to facilitate the driver deployment, issues termination commands, and subsequently removes the service to cover its tracks. Qihoo 360 is additionally targeted by blocking its network connections with specific firewall rules.

Attribution and Sophistication

According to security analysts from Elastic, this campaign is attributed to the Dragon Breath APT group. RONINGLOADER exhibits multiple fallback strategies to neutralize security defenses and evade detection tools, marking a notable advancement in its threat capacity. The use of Windows Protected Process Light behaviors and alternate code injection techniques highlights the malware's sophisticated approach to escape detection while maintaining effectiveness.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
7198366
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1625183
downloads
WinRAR

WinRAR

Streamline file management with fast compression, secure your documents, and save space.

5
735 reviews
696268
downloads
Minecraft

Minecraft

Shape environments, explore vast worlds, and survive against monsters with endless creativity.

5
750 reviews
485721
downloads

News and reviews for Desktop Windows

Copilot Vision Adds App Analysis to Windows 11 Taskbar

Microsoft's Copilot Vision now analyzes apps via the Windows 11 taskbar, offering suggestions based on content. Available for all PCs.

Read more

StarRupture Enters Steam Early Access with Unique Survival Mechanisms

StarRupture, from Creepy Jar, hits Steam Early Access, challenging players with survival tactics in extreme conditions.

Read more

Escape From Tarkov Tightens Terminal Mission Rules

Escape From Tarkov's Terminal mission sees stricter extraction rules, diverging from player requests for a simplified process.

Read more

Warhorse Studios Explores Unreal Engine for New Projects

Warhorse Studios hints at new projects with Unreal Engine, shifting away from CryEngine. Potential for diverse settings.

Read more

Wildgate and Total War: Three Kingdoms Free on Epic Games Store

Wildgate, an extraction shooter by Moonshot Games, is free on Epic Games Store until 2024-01-08. Claim now for an exciting gaming experience.

Read more

StarRupture Offers Early Access Discount for 2026 Launch

StarRupture by Creepy Jar launches in early access on 2026-01-06 with a 20% discount.

Read more

Hytale's World Generation V2 Set to Transform Gameplay

Hytale's new world generation debuts soon, offering players customizable, procedural landscapes. Impact expected in gaming innovation.

Read more

FlyOOBE Enhances AI Removal in Windows 11

FlyOOBE updates expand AI debloating options for Windows 11, introducing version 2.4 with new features and user risks.

Read more

Microsoft Turns Windows into AI Agents Hub

Microsoft revamps Windows for AI agents on 2026-01-05, enhancing productivity. Key changes include Agent 365 and Azure integrations.

Read more

Hackers Disrupt Siege X Again with Bogus Bans

Hackers infiltrate Siege X, send false ban messages to players, impacting gameplay and server stability.

Read more