Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Roning Loader

159
Global rank
197 infographic chevron month
Month rank
194 infographic chevron week
Week rank
0
IOCs

RoningLoader is a multi-stage Windows loader designed to operate quietly while preparing systems for deeper compromise. It abuses trusted system tools and interferes with security controls to reduce the chances of early detection. Instead of acting as a final payload, it creates conditions for follow-on malware to execute more effectively. Its use of staged execution and code injection allows attackers to blend into legitimate activity and escalate impact. This makes early behavioral detection critical before the attack chain progresses further.

Loader
Type
Unknown
Origin
1 February, 2026
First seen
12 June, 2026
Last seen

How to analyze Roning Loader with ANY.RUN

Type
Unknown
Origin
1 February, 2026
First seen
12 June, 2026
Last seen

IOCs

IP addresses
104.26.14.230
5.101.84.202
13.226.244.108
142.251.14.94
142.251.154.119
62.60.226.185
2.16.206.8
8.8.8.8
172.64.153.168
142.251.110.100
142.251.127.95
142.251.127.139
2.16.241.218
192.178.183.102
150.171.22.17
104.208.16.92
46.151.182.219
2.18.64.203
184.86.251.27
44.194.125.84
Hashes
9bcc7d4b69bde322809dd9cb29281bbeaad79071fb1e4f792dde685ed93b782f
ec22297e0c7a6c6ed0262010a9a67b3a1d2e60a79763f83d366821456e848c4e
5c3a5b578ab9fe853ead7040bc161929ea4f6902073ba2b8bb84487622b98923
87c640d3184c17d3b446a72d5f13d643a774b4ecc7afbedfd4e8da7795ea8077
ceebae7b8927a3227e5303cf5e0f1f7b34bb542ad7250ac03fbcde36ec2f1508
3cff4ac91288a0ff0c13278e73b282a64e83d089c5a61a45d483194ab336b852
602c4c7482de6479dd2e9793cda275e5e63d773dacd1eca689232ab7008fb4fb
cc5dacf370f324b77b50dddf5d995fd3c7b7a587cb2f55ac9f24c929d0cd531a
f957a4c261506484b53534a9be8931c02ec1a349b3f431a858f8215cecfec3f7
c04daeba7e7c4b711d33993ab4c51a2e087f98f4211aea0dcb3a216656ba0ab7
b7e25784d1b3a3653c618822715dae7cc86bf0b05fff0cf3c5d6a1fb169f0614
73b0b92179c61c26589b47e9732ce418b07edee3860ee5a2a5fb06f3b8aa9b26
7523c62abdb7628c5a9dad8f97d8d8c5c040ede36535e531a8a3748b6cae7e00
388c5c95f0f54f32b499c03a37aabfa5e0a31030ec70d0956a239942544b0eea
4a048d22363e0ec10fad2bab34adcd0edceba732d29f993ff897ed28a5653dda
8ff00d859349a3ea206706cdd3fa2762ae7c8efe2fdd33a95a72fee45aac6bc4
9d32032109ffc217b7dc49390bd01a067a49883843459356ebfb4d29ba696bf8
9111099efe9d5c9b391dc132b2faf0a3851a760d4106d5368e30ac744eb42706
884b04032e2e70a002956218e8ec3491f2b753c4596cee6e4894dc49afa0a681
2921a11f25dadaa24aa79a548e4e81508c2e5e56af2d833d65e2bcce448ce2f5
Domains
r1---sn-aigl6nz7.gvt1.com
r.bing.com
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com
clientservices.googleapis.com
www.bing.com
fonts.googleapis.com
files.bpcontent.cloud
clients2.googleusercontent.com
clients2.google.com
copilot.microsoft.com
cloudflare-dns.com
filescan.io
config.edge.skype.com
cdn.botpress.cloud
ntp.msn.com
accounts.google.com
redirector.gvt1.com
go.microsoft.com
settings-win.data.microsoft.com
www.google.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://urlhaus.abuse.ch/downloads/text_online/
http://178.16.54.109/go.exe
http://spasopro.at/lsge63sd3/bb.exe
http://178.16.54.109/mix.exe
http://196.251.107.104/spy.exe
https://agcestksa.com/ninja.exe
http://196.251.107.104/rtk.exe
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbtrjrydryt%2bapf3gspypfhbxr5xtqqus9tippmhxdiunkhmewnpyim8s8yceajtxtab8my1oj8mfwpz%2f7y%3d
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbq3l3%2f%2fa6adk8nray2gxzvayrhg4aqub6t%2b2v%2bxq3lso2d33ojhnyhhqoucezmaaaafuwohyjguzpcaaaaaaau%3d
https://www.bing.com/threshold/xls.aspx?t=5&dl=1&f=9&wsbc=1
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
https://settings-win.data.microsoft.com/settings/v3.0/wsd/updatehealthtools?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&sampleid=s:95271487&appver=10.0.19041.3626&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=sedimentpack&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://138.124.123.55/bin/screenconnect.clientsetup.exe
http://spasopro.at/lsge63sd3/ok.exe
https://www.bing.com/web/xlsc.aspx?t=5&dl=1&f=9&wsbc=1
http://clients2.google.com/time/1/current?cup2key=8:0py03ezverxeppdkqjolk6-vgkhvb1oexmfkvuxui3e&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
Last Seen at
Last Seen at

Recent blog posts

post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 1206
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 7344
comments 0
post image
Hunt Malware & Phishing Threats with ANY....
watchers 7035
comments 0

RoningLoader: The Multi-Stage Threat That Disarms Security and Opens the Door to Deeper Compromise

Key Takeaways

RoningLoader is built for stealthy multi-stage delivery: Rather than acting as a single obvious payload, it moves through several staged components, using legitimate Windows processes and installers to reduce suspicion and prepare the system for deeper compromise.

Defense tampering is part of the attack chain, not a side effect: RoningLoader interferes with Windows security controls, abuses Protected Process Light (PPL)-related techniques, and uses tools such as ClipUp.exe to help weaken Defender protections before the next payload is launched.

Trusted Windows tools help it blend in: The malware chain relies on binaries such as msiexec.exe and regsvr32.exe, allowing malicious activity to hide behind normal-looking system behavior and making static or signature-only detection less reliable.

Code injection raises the risk significantly: One of RoningLoader’s main goals is to place the next-stage payload inside a legitimate high-privilege process, such as TrustedInstaller.exe, helping attackers mask execution and operate with stronger privileges.

The final objective is broader compromise: RoningLoader is not the end of the intrusion. Public research links it to delivery of an updated gh0st RAT variant, while your analysts also observed clear preparation for follow-on payload execution even when the final stage was not fully visible in the sample.

Behavioral analysis is critical for catching RoningLoader early: Because the threat uses staged execution, security tool interference, and trusted process abuse, the clearest way to understand it is to observe the full chain in a sandbox and detect the behavior before the next payload gains a stronger foothold.

Observe RoningLoader detonated in the sandbox

RoningLoader RoningLoader fresh sample analysis in Interactive Sandbox

ANY.RUN’s Threat Intelligence Lookup is your pivot engine: By searching for RoningLoader process names, DLL artifacts, command-line strings, and behavioral patterns across millions of sandbox analyses, SOC and MSSP teams can identify related activity, expand detection coverage, and move from one alert to the broader intrusion chain faster.

Start your research with the threat name and browse sandbox analyses to watch behavior and gather indicators:

threatName:"roning"

RoningLoader RoningLoader sandbox analyses found in TI Lookup

What is RoningLoader Malware?

RoningLoader is a multi-stage Windows malware loader linked to a Dragon Breath campaign and publicly documented in 2025. Its role is not to create immediate visible damage on its own, but to quietly prepare an infected system for deeper compromise by helping attackers deliver and run additional malware while reducing the chance of early detection.

What makes RoningLoader notable is the way it blends into normal-looking system activity. Instead of behaving like a single obvious malicious file, it operates as part of a staged chain that helps attackers stay hidden, interfere with protections, and create safer conditions for the next payload to run. That makes it more dangerous than simple commodity malware, especially in environments that still rely heavily on static or signature-based detection.

Public reporting links RoningLoader to delivery of an updated gh0st RAT variant, which means the loader should be seen as an enabler of broader intrusion activity rather than the final objective. In practice, threats like this help attackers move from initial execution to longer-term access, surveillance, or follow-on malicious actions without exposing the full attack too early.

For businesses, the main concern is timing and visibility. A threat like RoningLoader can give attackers a head start by weakening defenses and hiding the transition to the next stage of the attack. That is why understanding the loader early matters: once the environment is prepared for follow-on malware, the incident becomes much harder to contain.

How RoningLoader Threatens Businesses and Organizations

RoningLoader increases risk by helping attackers move quietly from initial access to deeper compromise. Instead of acting as the final payload, it prepares the environment for what comes next and makes early detection harder.

Key risks include:

Reduced visibility early in the attack chain: Malicious activity can stay hidden while the next stage is prepared.

Security control interference: Attackers gain more room to operate before defenders see the full picture.

Follow-on payload delivery: The loader can help open the door to more serious malware and broader compromise.

Slower triage and investigation: Trusted system activity can make malicious behavior harder to recognize quickly.

Higher business impact: What starts as one infection can turn into a larger incident affecting operations, recovery time, and overall exposure.

The main danger with RoningLoader is not noise, but the quiet setup it gives attackers before the next stage begins.

Victimology: Which Industries Are Most at Risk?

RoningLoader activity was primarily aimed at Chinese-speaking users, with the malware delivered through trojanized installers impersonating trusted software such as Google Chrome and Microsoft Teams. The activity is linked to Dragon Breath, a threat actor associated with campaigns against Chinese-speaking targets, while broader reporting on the group connects it to activity involving the online gaming and gambling sectors.

That means the organizations most exposed are likely those with a mix of Windows-heavy environments, user-driven software installs, and limited early-stage behavioral visibility. The risk is especially relevant for:

Online gaming and gambling businesses: Dragon Breath has been linked to this broader ecosystem in prior reporting.

Organizations with Chinese-speaking user or employee bases: the campaign was reported as primarily targeting Chinese-speaking users.

Enterprises where users frequently download common software: trojanized installers work best in environments where trusted apps are often installed or updated.

Teams relying heavily on signature-based protection: RoningLoader’s staged, evasive behavior makes early detection harder without behavioral analysis.

Rather than targeting one sector as narrowly as some ransomware families do, RoningLoader appears more dangerous in environments where trusted software lures, user execution, and weak early visibility can help a staged loader operate before defenders recognize the full chain.

How Can Businesses Proactively Protect Against RoningLoader Malware

Threat Intelligence Lookup helps security teams search across millions of sandbox analyses using threat names, file names, command-line artifacts, and other behavioral indicators tied to RoningLoader. This makes it easier to find related samples, uncover activity patterns, and expand detection coverage beyond a single alert. RoningLoader’s staged execution and use of trusted Windows tools make this kind of pivoting especially useful.

threatName:"roning"

RoningLoader RoningLoader industries and submission countries revealed inside TI Lookup

Threat Intelligence Feeds deliver continuously updated machine-readable indicators into SIEM, EDR, SOAR, and other security tools, helping organizations block known malicious infrastructure and enrich detections faster. For a loader like RoningLoader, that means defenders can improve visibility into related activity and respond earlier in the attack chain.

RoningLoader TI Feeds providing 99% unique threat data

Behavior-based detection: Monitor for suspicious defense interference, abuse of legitimate Windows binaries, and unusual parent-child process chains. RoningLoader was documented using evasion methods and Defender tampering rather than relying on one obvious malicious action.

Application control and software validation: Restrict unapproved software installs and verify installers, since the campaign used trojanized software lures masquerading as trusted applications.

Least-privilege access: Limit unnecessary administrative rights so attackers have fewer opportunities to interfere with protections or move to more privileged stages. This is an inference from the reported abuse of high-privilege processes and security controls.

EDR hardening and monitoring: Make sure endpoint tools are configured to detect tampering attempts and suspicious abuse of native Windows components. Elastic reports the campaign targeted endpoint protections and used multiple evasive layers.

User awareness around software downloads: Train employees to avoid downloading installers from unofficial sources, especially when attackers impersonate well-known software brands to trigger execution.

How RoningLoader Gets in the System and Functions

RoningLoader’s operators do not appear to rely on one loud or obvious execution path. The malware is delivered through trojanized software installers disguised as trusted applications such as Google Chrome and Microsoft Teams, while the broader campaign was reported as primarily targeting Chinese-speaking users. That approach helps the infection begin under the cover of normal-looking software installation activity.

Once inside the system, RoningLoader’s goal is not immediate destruction, but quiet preparation for the next payload. Its main purpose is to weaken defenses, blend into legitimate Windows activity, and create safer conditions for follow-on malware to run with less visibility. The loader is linked to the delivery of an updated gh0st RAT variant.

RoningLoader’s execution flow can be broken into several distinct phases:

Phase 1: Trojanized Installation and Stage Launch

The infection begins with a fake installer that appears legitimate to the victim. For instance, the file may be launched through msiexec.exe, after which a secondary malicious component can start.

Phase 2: Payload Staging and Hidden Component Preparation

After launch, the malware prepares additional components needed for the rest of the chain. A dedicated directory is created and multiple files are dropped there, including a malicious DLL and an encrypted file used later in execution.

Phase 3: Defense Interference and Evasion

Before moving to the next payload, RoningLoader interferes with system protections. Research describes multiple evasion layers aimed at neutralizing endpoint security products, including PPL abuse, a legitimately signed driver, and custom WDAC policies used to interfere with Defender and evade Chinese EDR tools. This stage also included actions intended to weaken Windows protections and disrupt antivirus-related processes.

Phase 4: Trusted Process Abuse and Injection Preparation

RoningLoader then shifts toward execution under trusted system activity. Analysts observed the malware abusing legitimate Windows tools and preparing the next malicious component for injection into a high-privilege process.

Phase 5: Follow-On Payload Delivery

The final purpose of the chain is to launch the next malware stage, not to stop at the loader itself. RoningLoader was used to deploy an updated gh0st RAT variant, making the loader a bridge between the initial lure and deeper compromise.

Sandbox Analysis of RoningLoader Malware Sample

See full execution chain of RoningLoader

RoningLoader ANY.RUN sandbox revealing RoningLoader behavior in real time

The analyzed sample begins with 1.exe, which is launched as an MSI installer through msiexec.exe. After the installation environment is prepared, execution continues with a process named Snieoatwtregoable.exe, which acts as the next malicious stage in the chain.

RoningLoader Snieoatwtregoable.exe revealed inside ANY.RUN sandbox

This installer creates a new directory at C:\Program Files\Snieoatwtregoable. Inside it, two files are placed: a malicious DLL named Snieoatwtregoable.dll and an encrypted file called tp.png. From there, the malware initiates regsvr32.exe with the malicious DLL, using the process to carry out decryption and code injection.

At the same time, the malware interferes with Windows security mechanisms to make later stages more likely to succeed. A batch file named 1.bat disables User Account Control (UAC), reducing friction for malicious actions that follow. Another component, 1.dll, is copied to C:\Windows\System32\Wow64\Wow64Log.dll, allowing it to be loaded later by WOW64 processes. The malware also attempts to terminate a list of antivirus-related processes.

RoningLoader Windows Defender settings modified by the threat

The chain then moves deeper into defense tampering. regsvr32.exe repeatedly launches ClipUp.exe with a command line containing the -ppl parameter and the path C:\ProgramData\roming\MsMpEng.exe. These repeated executions are aimed at modifying Windows Defender-related components and weakening the platform’s protective mechanisms.

After interfering with antivirus protections, RoningLoader proceeds with its core loader function. For this stage, it uses the following command:

regsvr32.exe /S "C:\ProgramData\Roning\goldendays.dll"

RoningLoader Regsvr32.exe used to proceed with the core loader function

The purpose of this component is to inject the next payload into a legitimate, high-privilege system process in order to hide malicious activity behind trusted execution. To achieve this, RoningLoader first identifies a suitable target process. In the analyzed example, that process is TrustedInstaller.exe. The malware then reads the contents of C:\ProgramData\Roning\trustinstaller.bin and injects that payload into the target process.

RoningLoader ANY.RUN sandbox shows the injection of payload into the target process

Conclusion

RoningLoader is not loud, obvious malware. It is quiet, staged, and built to stay out of sight while preparing the next step of the attack. That is what makes it dangerous in environments where legitimate system activity can easily mask malicious behavior.

Defending against it requires more than tools. It requires context. And context is exactly what behavioral analysis and strong threat intelligence provide.

For businesses and security teams, the key lesson from RoningLoader is timing. The most effective defenses are the ones that work before or during the early stages of execution: behavior-based detection, proactive threat intelligence, and security controls that can spot trusted tool abuse before the next payload is delivered.

Use TI Lookup to start gathering actionable threat intelligence on the malware affecting your industry and region: Sign up to ANY.RUN

HAVE A LOOK AT

Fog Ransomware screenshot
Fog is a ransomware strain that locks and steals sensitive information both on Windows and Linux endpoints. The medial ransom demand is $220,000. The medial payment is $100,000. First spotted in the spring of 2024, it was used to attack educational organizations in the USA, later expanding on other sectors and countries. Main distribution method — compromised VPN credentials.
Read More
Spyware screenshot
Spyware
spyware
Spyware is a stealth form of malware whose primary objective is to gather sensitive information, such as personal data, login credentials, and financial details, by monitoring user activities and exploiting system vulnerabilities. Spyware operates secretly in the background, evading detection while transmitting collected data to cybercriminals, who can then use it for malicious purposes like identity theft, financial fraud, or espionage.
Read More
MetaStealer screenshot
MetaStealer
metastealer
MetaStealer is an info-stealing malware primarily targeting sensitive data like login credentials, payment details, and browser history. It typically infects systems via phishing emails or malicious downloads and can exfiltrate data to a command and control (C2) server. MetaStealer is known for its stealthy techniques, including evasion and persistence mechanisms, which make it difficult to detect. This malware has been actively used in various cyberattacks, particularly for financial theft and credential harvesting from individuals and organizations.
Read More
Cephalus screenshot
Cephalus
cephalus
Cephalus is a targeted ransomware threat discovered in 2025. It’s known for infiltrating organizations that deal with sensitive data through compromised RDP access. It leverages DLL sideloading with a legitimate SentinelOne executable. Cephalus is able to exfiltrate data and destroy backup options. Its payload is also tailored to each victim, which makes identification and mitigation more complex.
Read More
GuLoader screenshot
GuLoader
guloader
GuLoader is an advanced downloader written in shellcode. It’s used by criminals to distribute other malware, notably trojans, on a large scale. It’s infamous for using anti-detection and anti-analysis capabilities.
Read More
Salty 2FA screenshot
Salty 2FA
salty2fa
Salty 2FA is a sophisticated Phishing-as-a-Service (PhaaS) framework tailored to hijack user sessions, steal credentials, and gain unauthorized access to corporate systems. Delivered primarily via targeted emails, this kit employs multi-stage evasion tactics, making it a stealthy tool for cybercriminals aiming at high-value enterprise accounts.
Read More