Skip to main content

Threats Tagged 'thread-pool injection'

View all threats tagged with 'thread-pool injection'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: thread-pool injection

Threats Tagged 'thread-pool injection'

Click on any threat for detailed analysis and mitigation recommendations

RONINGLOADER is a sophisticated multi-stage malware loader used by the DragonBreath APT group to deploy an updated variant of the gh0st RAT. It begins infection via trojanized NSIS installers disguised as legitimate software and employs advanced evasion techniques including signed driver abuse, thread-pool injection, and Protected Process Light (PPL) exploitation to disable Microsoft Defender. The loader terminates antivirus processes, applies custom Windows Defender Application Control (WDAC) policies, and injects payloads into trusted system processes to avoid detection. This campaign targets Chinese EDR tools but demonstrates advanced tactics that could be adapted elsewhere. The malware’s complexity and stealth capabilities pose a medium severity threat, with potential impacts on confidentiality and integrity. European organizations using Windows environments with Microsoft Defender could be at risk, especially those in critical infrastructure and government sectors. Mitigation requires tailored detection of abnormal driver behavior, WDAC policy monitoring, and restricting installation of unsigned drivers. Countries with high adoption of Microsoft Defender and strategic geopolitical interest in China-related espionage are most likely affected.

Join the discussion

Showing 1 to 1 of 1 result

Filters:Tag: thread-pool injection
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses