Threats Tagged 'thread-pool injection'
View all threats tagged with 'thread-pool injection'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'thread-pool injection'
Click on any threat for detailed analysis and mitigation recommendations
RONINGLOADER is a sophisticated multi-stage malware loader used by the DragonBreath APT group to deploy an updated variant of the gh0st RAT. It begins infection via trojanized NSIS installers disguised as legitimate software and employs advanced evasion techniques including signed driver abuse, thread-pool injection, and Protected Process Light (PPL) exploitation to disable Microsoft Defender. The loader terminates antivirus processes, applies custom Windows Defender Application Control (WDAC) policies, and injects payloads into trusted system processes to avoid detection. This campaign targets Chinese EDR tools but demonstrates advanced tactics that could be adapted elsewhere. The malware’s complexity and stealth capabilities pose a medium severity threat, with potential impacts on confidentiality and integrity. European organizations using Windows environments with Microsoft Defender could be at risk, especially those in critical infrastructure and government sectors. Mitigation requires tailored detection of abnormal driver behavior, WDAC policy monitoring, and restricting installation of unsigned drivers. Countries with high adoption of Microsoft Defender and strategic geopolitical interest in China-related espionage are most likely affected. Join the discussion | AlienVault OTX General | 11/19/2025, 08:54:30 UTC Added: 11/19/2025, 09:17:04 UTC |
Showing 1 to 1 of 1 result