Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Roning Loader

159
Global rank
197
Month rank
196 infographic chevron week
Week rank
0
IOCs

RoningLoader is a multi-stage Windows loader designed to operate quietly while preparing systems for deeper compromise. It abuses trusted system tools and interferes with security controls to reduce the chances of early detection. Instead of acting as a final payload, it creates conditions for follow-on malware to execute more effectively. Its use of staged execution and code injection allows attackers to blend into legitimate activity and escalate impact. This makes early behavioral detection critical before the attack chain progresses further.

Loader
Type
Unknown
Origin
1 February, 2026
First seen
12 June, 2026
Last seen

How to analyze Roning Loader with ANY.RUN

Type
Unknown
Origin
1 February, 2026
First seen
12 June, 2026
Last seen

IOCs

IP addresses
104.26.14.230
5.101.84.202
13.226.244.108
142.251.14.94
142.251.154.119
62.60.226.185
2.16.206.8
8.8.8.8
172.64.153.168
142.251.110.100
142.251.127.95
142.251.127.139
2.16.241.218
192.178.183.102
150.171.22.17
104.208.16.92
46.151.182.219
2.18.64.203
184.86.251.27
44.194.125.84
Hashes
9bcc7d4b69bde322809dd9cb29281bbeaad79071fb1e4f792dde685ed93b782f
ec22297e0c7a6c6ed0262010a9a67b3a1d2e60a79763f83d366821456e848c4e
5c3a5b578ab9fe853ead7040bc161929ea4f6902073ba2b8bb84487622b98923
87c640d3184c17d3b446a72d5f13d643a774b4ecc7afbedfd4e8da7795ea8077
ceebae7b8927a3227e5303cf5e0f1f7b34bb542ad7250ac03fbcde36ec2f1508
3cff4ac91288a0ff0c13278e73b282a64e83d089c5a61a45d483194ab336b852
602c4c7482de6479dd2e9793cda275e5e63d773dacd1eca689232ab7008fb4fb
cc5dacf370f324b77b50dddf5d995fd3c7b7a587cb2f55ac9f24c929d0cd531a
f957a4c261506484b53534a9be8931c02ec1a349b3f431a858f8215cecfec3f7
c04daeba7e7c4b711d33993ab4c51a2e087f98f4211aea0dcb3a216656ba0ab7
b7e25784d1b3a3653c618822715dae7cc86bf0b05fff0cf3c5d6a1fb169f0614
73b0b92179c61c26589b47e9732ce418b07edee3860ee5a2a5fb06f3b8aa9b26
7523c62abdb7628c5a9dad8f97d8d8c5c040ede36535e531a8a3748b6cae7e00
388c5c95f0f54f32b499c03a37aabfa5e0a31030ec70d0956a239942544b0eea
4a048d22363e0ec10fad2bab34adcd0edceba732d29f993ff897ed28a5653dda
8ff00d859349a3ea206706cdd3fa2762ae7c8efe2fdd33a95a72fee45aac6bc4
9d32032109ffc217b7dc49390bd01a067a49883843459356ebfb4d29ba696bf8
9111099efe9d5c9b391dc132b2faf0a3851a760d4106d5368e30ac744eb42706
884b04032e2e70a002956218e8ec3491f2b753c4596cee6e4894dc49afa0a681
2921a11f25dadaa24aa79a548e4e81508c2e5e56af2d833d65e2bcce448ce2f5
Domains
r1---sn-aigl6nz7.gvt1.com
r.bing.com
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com
clientservices.googleapis.com
www.bing.com
fonts.googleapis.com
files.bpcontent.cloud
clients2.googleusercontent.com
clients2.google.com
copilot.microsoft.com
cloudflare-dns.com
filescan.io
config.edge.skype.com
cdn.botpress.cloud
ntp.msn.com
accounts.google.com
redirector.gvt1.com
go.microsoft.com
settings-win.data.microsoft.com
www.google.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://urlhaus.abuse.ch/downloads/text_online/
http://178.16.54.109/go.exe
http://spasopro.at/lsge63sd3/bb.exe
http://178.16.54.109/mix.exe
http://196.251.107.104/spy.exe
https://agcestksa.com/ninja.exe
http://196.251.107.104/rtk.exe
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbtrjrydryt%2bapf3gspypfhbxr5xtqqus9tippmhxdiunkhmewnpyim8s8yceajtxtab8my1oj8mfwpz%2f7y%3d
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbq3l3%2f%2fa6adk8nray2gxzvayrhg4aqub6t%2b2v%2bxq3lso2d33ojhnyhhqoucezmaaaafuwohyjguzpcaaaaaaau%3d
https://www.bing.com/threshold/xls.aspx?t=5&dl=1&f=9&wsbc=1
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
https://settings-win.data.microsoft.com/settings/v3.0/wsd/updatehealthtools?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&sampleid=s:95271487&appver=10.0.19041.3626&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=sedimentpack&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://138.124.123.55/bin/screenconnect.clientsetup.exe
http://spasopro.at/lsge63sd3/ok.exe
https://www.bing.com/web/xlsc.aspx?t=5&dl=1&f=9&wsbc=1
http://clients2.google.com/time/1/current?cup2key=8:0py03ezverxeppdkqjolk6-vgkhvb1oexmfkvuxui3e&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
Last Seen at
Last Seen at

Recent blog posts

post image
Mirage2FA Hijacks Companies’ Microsoft 365 Se...
watchers 379
comments 0
post image
Intelligence-Driven SOC: Modernizing Threat M...
watchers 11437
comments 0
post image
Supply Chain Security: How ANY.RUN Helps US a...
watchers 6548
comments 0

RoningLoader: The Multi-Stage Threat That Disarms Security and Opens the Door to Deeper Compromise

Key Takeaways

RoningLoader is built for stealthy multi-stage delivery: Rather than acting as a single obvious payload, it moves through several staged components, using legitimate Windows processes and installers to reduce suspicion and prepare the system for deeper compromise.

Defense tampering is part of the attack chain, not a side effect: RoningLoader interferes with Windows security controls, abuses Protected Process Light (PPL)-related techniques, and uses tools such as ClipUp.exe to help weaken Defender protections before the next payload is launched.

Trusted Windows tools help it blend in: The malware chain relies on binaries such as msiexec.exe and regsvr32.exe, allowing malicious activity to hide behind normal-looking system behavior and making static or signature-only detection less reliable.

Code injection raises the risk significantly: One of RoningLoader’s main goals is to place the next-stage payload inside a legitimate high-privilege process, such as TrustedInstaller.exe, helping attackers mask execution and operate with stronger privileges.

The final objective is broader compromise: RoningLoader is not the end of the intrusion. Public research links it to delivery of an updated gh0st RAT variant, while your analysts also observed clear preparation for follow-on payload execution even when the final stage was not fully visible in the sample.

Behavioral analysis is critical for catching RoningLoader early: Because the threat uses staged execution, security tool interference, and trusted process abuse, the clearest way to understand it is to observe the full chain in a sandbox and detect the behavior before the next payload gains a stronger foothold.

Observe RoningLoader detonated in the sandbox

RoningLoader RoningLoader fresh sample analysis in Interactive Sandbox

ANY.RUN’s Threat Intelligence Lookup is your pivot engine: By searching for RoningLoader process names, DLL artifacts, command-line strings, and behavioral patterns across millions of sandbox analyses, SOC and MSSP teams can identify related activity, expand detection coverage, and move from one alert to the broader intrusion chain faster.

Start your research with the threat name and browse sandbox analyses to watch behavior and gather indicators:

threatName:"roning"

RoningLoader RoningLoader sandbox analyses found in TI Lookup

What is RoningLoader Malware?

RoningLoader is a multi-stage Windows malware loader linked to a Dragon Breath campaign and publicly documented in 2025. Its role is not to create immediate visible damage on its own, but to quietly prepare an infected system for deeper compromise by helping attackers deliver and run additional malware while reducing the chance of early detection.

What makes RoningLoader notable is the way it blends into normal-looking system activity. Instead of behaving like a single obvious malicious file, it operates as part of a staged chain that helps attackers stay hidden, interfere with protections, and create safer conditions for the next payload to run. That makes it more dangerous than simple commodity malware, especially in environments that still rely heavily on static or signature-based detection.

Public reporting links RoningLoader to delivery of an updated gh0st RAT variant, which means the loader should be seen as an enabler of broader intrusion activity rather than the final objective. In practice, threats like this help attackers move from initial execution to longer-term access, surveillance, or follow-on malicious actions without exposing the full attack too early.

For businesses, the main concern is timing and visibility. A threat like RoningLoader can give attackers a head start by weakening defenses and hiding the transition to the next stage of the attack. That is why understanding the loader early matters: once the environment is prepared for follow-on malware, the incident becomes much harder to contain.

How RoningLoader Threatens Businesses and Organizations

RoningLoader increases risk by helping attackers move quietly from initial access to deeper compromise. Instead of acting as the final payload, it prepares the environment for what comes next and makes early detection harder.

Key risks include:

Reduced visibility early in the attack chain: Malicious activity can stay hidden while the next stage is prepared.

Security control interference: Attackers gain more room to operate before defenders see the full picture.

Follow-on payload delivery: The loader can help open the door to more serious malware and broader compromise.

Slower triage and investigation: Trusted system activity can make malicious behavior harder to recognize quickly.

Higher business impact: What starts as one infection can turn into a larger incident affecting operations, recovery time, and overall exposure.

The main danger with RoningLoader is not noise, but the quiet setup it gives attackers before the next stage begins.

Victimology: Which Industries Are Most at Risk?

RoningLoader activity was primarily aimed at Chinese-speaking users, with the malware delivered through trojanized installers impersonating trusted software such as Google Chrome and Microsoft Teams. The activity is linked to Dragon Breath, a threat actor associated with campaigns against Chinese-speaking targets, while broader reporting on the group connects it to activity involving the online gaming and gambling sectors.

That means the organizations most exposed are likely those with a mix of Windows-heavy environments, user-driven software installs, and limited early-stage behavioral visibility. The risk is especially relevant for:

Online gaming and gambling businesses: Dragon Breath has been linked to this broader ecosystem in prior reporting.

Organizations with Chinese-speaking user or employee bases: the campaign was reported as primarily targeting Chinese-speaking users.

Enterprises where users frequently download common software: trojanized installers work best in environments where trusted apps are often installed or updated.

Teams relying heavily on signature-based protection: RoningLoader’s staged, evasive behavior makes early detection harder without behavioral analysis.

Rather than targeting one sector as narrowly as some ransomware families do, RoningLoader appears more dangerous in environments where trusted software lures, user execution, and weak early visibility can help a staged loader operate before defenders recognize the full chain.

How Can Businesses Proactively Protect Against RoningLoader Malware

Threat Intelligence Lookup helps security teams search across millions of sandbox analyses using threat names, file names, command-line artifacts, and other behavioral indicators tied to RoningLoader. This makes it easier to find related samples, uncover activity patterns, and expand detection coverage beyond a single alert. RoningLoader’s staged execution and use of trusted Windows tools make this kind of pivoting especially useful.

threatName:"roning"

RoningLoader RoningLoader industries and submission countries revealed inside TI Lookup

Threat Intelligence Feeds deliver continuously updated machine-readable indicators into SIEM, EDR, SOAR, and other security tools, helping organizations block known malicious infrastructure and enrich detections faster. For a loader like RoningLoader, that means defenders can improve visibility into related activity and respond earlier in the attack chain.

RoningLoader TI Feeds providing 99% unique threat data

Behavior-based detection: Monitor for suspicious defense interference, abuse of legitimate Windows binaries, and unusual parent-child process chains. RoningLoader was documented using evasion methods and Defender tampering rather than relying on one obvious malicious action.

Application control and software validation: Restrict unapproved software installs and verify installers, since the campaign used trojanized software lures masquerading as trusted applications.

Least-privilege access: Limit unnecessary administrative rights so attackers have fewer opportunities to interfere with protections or move to more privileged stages. This is an inference from the reported abuse of high-privilege processes and security controls.

EDR hardening and monitoring: Make sure endpoint tools are configured to detect tampering attempts and suspicious abuse of native Windows components. Elastic reports the campaign targeted endpoint protections and used multiple evasive layers.

User awareness around software downloads: Train employees to avoid downloading installers from unofficial sources, especially when attackers impersonate well-known software brands to trigger execution.

How RoningLoader Gets in the System and Functions

RoningLoader’s operators do not appear to rely on one loud or obvious execution path. The malware is delivered through trojanized software installers disguised as trusted applications such as Google Chrome and Microsoft Teams, while the broader campaign was reported as primarily targeting Chinese-speaking users. That approach helps the infection begin under the cover of normal-looking software installation activity.

Once inside the system, RoningLoader’s goal is not immediate destruction, but quiet preparation for the next payload. Its main purpose is to weaken defenses, blend into legitimate Windows activity, and create safer conditions for follow-on malware to run with less visibility. The loader is linked to the delivery of an updated gh0st RAT variant.

RoningLoader’s execution flow can be broken into several distinct phases:

Phase 1: Trojanized Installation and Stage Launch

The infection begins with a fake installer that appears legitimate to the victim. For instance, the file may be launched through msiexec.exe, after which a secondary malicious component can start.

Phase 2: Payload Staging and Hidden Component Preparation

After launch, the malware prepares additional components needed for the rest of the chain. A dedicated directory is created and multiple files are dropped there, including a malicious DLL and an encrypted file used later in execution.

Phase 3: Defense Interference and Evasion

Before moving to the next payload, RoningLoader interferes with system protections. Research describes multiple evasion layers aimed at neutralizing endpoint security products, including PPL abuse, a legitimately signed driver, and custom WDAC policies used to interfere with Defender and evade Chinese EDR tools. This stage also included actions intended to weaken Windows protections and disrupt antivirus-related processes.

Phase 4: Trusted Process Abuse and Injection Preparation

RoningLoader then shifts toward execution under trusted system activity. Analysts observed the malware abusing legitimate Windows tools and preparing the next malicious component for injection into a high-privilege process.

Phase 5: Follow-On Payload Delivery

The final purpose of the chain is to launch the next malware stage, not to stop at the loader itself. RoningLoader was used to deploy an updated gh0st RAT variant, making the loader a bridge between the initial lure and deeper compromise.

Sandbox Analysis of RoningLoader Malware Sample

See full execution chain of RoningLoader

RoningLoader ANY.RUN sandbox revealing RoningLoader behavior in real time

The analyzed sample begins with 1.exe, which is launched as an MSI installer through msiexec.exe. After the installation environment is prepared, execution continues with a process named Snieoatwtregoable.exe, which acts as the next malicious stage in the chain.

RoningLoader Snieoatwtregoable.exe revealed inside ANY.RUN sandbox

This installer creates a new directory at C:\Program Files\Snieoatwtregoable. Inside it, two files are placed: a malicious DLL named Snieoatwtregoable.dll and an encrypted file called tp.png. From there, the malware initiates regsvr32.exe with the malicious DLL, using the process to carry out decryption and code injection.

At the same time, the malware interferes with Windows security mechanisms to make later stages more likely to succeed. A batch file named 1.bat disables User Account Control (UAC), reducing friction for malicious actions that follow. Another component, 1.dll, is copied to C:\Windows\System32\Wow64\Wow64Log.dll, allowing it to be loaded later by WOW64 processes. The malware also attempts to terminate a list of antivirus-related processes.

RoningLoader Windows Defender settings modified by the threat

The chain then moves deeper into defense tampering. regsvr32.exe repeatedly launches ClipUp.exe with a command line containing the -ppl parameter and the path C:\ProgramData\roming\MsMpEng.exe. These repeated executions are aimed at modifying Windows Defender-related components and weakening the platform’s protective mechanisms.

After interfering with antivirus protections, RoningLoader proceeds with its core loader function. For this stage, it uses the following command:

regsvr32.exe /S "C:\ProgramData\Roning\goldendays.dll"

RoningLoader Regsvr32.exe used to proceed with the core loader function

The purpose of this component is to inject the next payload into a legitimate, high-privilege system process in order to hide malicious activity behind trusted execution. To achieve this, RoningLoader first identifies a suitable target process. In the analyzed example, that process is TrustedInstaller.exe. The malware then reads the contents of C:\ProgramData\Roning\trustinstaller.bin and injects that payload into the target process.

RoningLoader ANY.RUN sandbox shows the injection of payload into the target process

Conclusion

RoningLoader is not loud, obvious malware. It is quiet, staged, and built to stay out of sight while preparing the next step of the attack. That is what makes it dangerous in environments where legitimate system activity can easily mask malicious behavior.

Defending against it requires more than tools. It requires context. And context is exactly what behavioral analysis and strong threat intelligence provide.

For businesses and security teams, the key lesson from RoningLoader is timing. The most effective defenses are the ones that work before or during the early stages of execution: behavior-based detection, proactive threat intelligence, and security controls that can spot trusted tool abuse before the next payload is delivered.

Use TI Lookup to start gathering actionable threat intelligence on the malware affecting your industry and region: Sign up to ANY.RUN

HAVE A LOOK AT

BlackMoon screenshot
BlackMoon
blackmoon
BlackMoon also known as KrBanker is a trojan aimed at stealing payment credentials. It specializes in man-in-the-browser (MitB) attacks, web injection, and credential theft to compromise users' online banking accounts. It was first noticed in early 2014 attacking banks in South Korea and has impressively evolved since by adding a number of new infiltration techniques and information stealing methods.
Read More
Lumma screenshot
Lumma
lumma
Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat.
Read More
Stealc screenshot
Stealc
stealc
Stealc is a stealer malware that targets victims’ sensitive data, which it exfiltrates from browsers, messaging apps, and other software. The malware is equipped with advanced features, including fingerprinting, control panel, evasion mechanisms, string obfuscation, etc. Stealc establishes persistence and communicates with its C2 server through HTTP POST requests.
Read More
INC Ransomware screenshot
INC Ransomware is a ransomware-as-a-service (RaaS) spotted in mid-2023. It targets industries like retail, real estate, finance, healthcare, and education, primarily in the U.S. and UK. It encrypts and exfiltrates data demanding a ransom. It employs advanced evasion techniques, destroys backup, and abuses legitimate system tools at all the stages of the kill chain.
Read More
Quasar RAT screenshot
Quasar RAT
quasar trojan rat
Quasar is a very popular RAT in the world thanks to its code being available in open-source. This malware can be used to control the victim’s computer remotely.
Read More
MassLogger screenshot
MassLogger
masslogger
MassLogger is a credential stealer and keylogger first identified in April 2020. It has been actively used in cyber campaigns to exfiltrate sensitive information from compromised systems. It is designed for easy use by less tech-savvy actors and is prominent for the capability of spreading via USB drives. It targets both individuals and organizations in various industries, mostly in Europe and the USA.
Read More