Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Roning Loader

153
Global rank
125 infographic chevron month
Month rank
134 infographic chevron week
Week rank

RoningLoader is a multi-stage Windows loader designed to operate quietly while preparing systems for deeper compromise. It abuses trusted system tools and interferes with security controls to reduce the chances of early detection. Instead of acting as a final payload, it creates conditions for follow-on malware to execute more effectively. Its use of staged execution and code injection allows attackers to blend into legitimate activity and escalate impact. This makes early behavioral detection critical before the attack chain progresses further.

Loader
Type
Unknown
Origin
1 February, 2026
First seen
29 September, 2026
Last seen

How to analyze Roning Loader with ANY.RUN

Type
Unknown
Origin
1 February, 2026
First seen
29 September, 2026
Last seen

IOCs

IP addresses
89.106.83.205
204.44.93.119
118.107.1.203
104.249.10.144
91.92.240.17
205.185.115.131
142.251.127.94
120.76.143.184
130.17.8.71
194.150.166.178
185.27.134.24
205.185.113.69
195.177.94.112
188.114.96.3
132.243.212.233
83.171.226.136
45.74.3.37
158.94.211.110
180.235.151.11
142.250.154.138
Hashes
a8a284f377cb9f21c53e5553234ecb693dc4c2c38f3306b6cde4aead5e05e913
0b41f69e6564b9c89b1b344744c5b06eb4adc0e584028909286d2b936e1afed5
f8bf41177a5f5e808a7ccb648b51080b031f15ca8018d91a576263d6cc626eb6
92804faaab2175dc501d73e814663058c78c0a042675a8937266357bcfb96c50
319cff6e7a31f0f2a41c475dca42890aa5d19fe16017e2290f8c1d4e14f76481
aac73b3148f6d1d7111dbca32099f68d26c644c6813ae1e4f05f6579aa2663fe
46079c0a1b660fc187aafd760707f369d0b60d424d878c57685545a3fce95819
2eb96422375f1a7b687115b132a4005d2e7d3d5dc091fb0eb22a6471e712848e
5c9bc70586ad538b0df1fcf5d6f1f3527450ae16935aa34bd7eb494b4f1b2db9
72c639d1afda32a65143bcbe016fe5d8b46d17924f5f5190eb04efe954c1199a
7102f8d9d0f3f689129d7fe071b234077fba4dd3687071d1e2aeaa137b123f86
058eb7ce88c22d2ff7d3e61e6593ca4e3d6df449f984bf251d9432665e1517d1
f5183b8d7462c01031992267fe85680ab9c5b279bedc0b25ab219f7c2184766f
14f92b911f9fe774720461eec5bb4761ae6bfc9445c67e30bf624a8694b4b1da
e2ce89b3e68b003cb27e2c5652ccba073c8938bef194e51830539b2464a3f676
5494adf651fc64e3aa6c08e38165d8dbfec52056cdf4fadae90b76b0e6816a33
bf0386f6e9b4a35fefe5fe917e2be7c64867efe24521f18e4567f8af5f6dd5e5
129b343ff412f0b5af597face89caba3a70092e7ca758be9ebc7d1e6d1443c3c
b37602dbb924bb94df0d9745d13fcace8a6642397fb738fbe02a88f667f3ab66
78081921fbce9b9ecf1691a0eedc2b5be2e3a4ebd6bbe9e7f5666e22c5bdc6ca
Domains
mitraperijinan.co.id
client.wns.windows.com
minpop.com
pizzariatrattoria.com
tapestryoftruth.com
r2---sn-a0jpm-a0mz.gvt1.com
www.intelligradeeducation.vicentecisnerospub.com
lavos.life
od.lk
www.microsoft.com
crazypianoswebshop.nl
universalmobility.pro
google.com
cloudstorage-hub.com
www.update.microsoft.com
geoxsecurity.ro
pub-5fd52250a6494c859025a3cd39713703.r2.dev
dl.360safe.com
rubburizee.es
cloudimagehostingupdatesrealted.yzz.me
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20secure%20server%20ca%202026.crl
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://login.live.com/ppsecure/deviceaddcredential.srf
https://activation-v2.sls.microsoft.com/slactivateproduct/slactivateproduct.asmx?configextension=retail
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://maper.info/26tkr5
https://www.google.com/
https://urlhaus.abuse.ch/downloads/text/
http://91.92.242.236/files-129312398/files/file_ad6ea8ff7c86f0ad.exe
http://91.92.242.236/files-129312398/files/file_7c23b7b64f4c1870.exe
http://107.174.33.14/96/img_182048.png
http://104.168.70.171/55/img_200534.png
http://5.175.169.207/img_113850.png
http://62.60.226.140/files/8351821253/nqa0sjr.exe
http://172.245.209.194/56/img_232634.png
http://193.90.12.80/ns1.jpg
http://193.90.12.80/ns3.jpg
http://62.60.226.140/files/5279938618/dazaupk.exe
Last Seen at
Last Seen at

Recent blog posts

post image
Threat Coverage Digest: New Malware Reports a...
watchers 7089
comments 0
post image
Phishing Response Protocol: 3 Essential SOC S...
watchers 9185
comments 0
post image
Major Cyber Attacks in September 2026: US and...
watchers 13311
comments 0

RoningLoader: The Multi-Stage Threat That Disarms Security and Opens the Door to Deeper Compromise

Key Takeaways

RoningLoader is built for stealthy multi-stage delivery: Rather than acting as a single obvious payload, it moves through several staged components, using legitimate Windows processes and installers to reduce suspicion and prepare the system for deeper compromise.

Defense tampering is part of the attack chain, not a side effect: RoningLoader interferes with Windows security controls, abuses Protected Process Light (PPL)-related techniques, and uses tools such as ClipUp.exe to help weaken Defender protections before the next payload is launched.

Trusted Windows tools help it blend in: The malware chain relies on binaries such as msiexec.exe and regsvr32.exe, allowing malicious activity to hide behind normal-looking system behavior and making static or signature-only detection less reliable.

Code injection raises the risk significantly: One of RoningLoader’s main goals is to place the next-stage payload inside a legitimate high-privilege process, such as TrustedInstaller.exe, helping attackers mask execution and operate with stronger privileges.

The final objective is broader compromise: RoningLoader is not the end of the intrusion. Public research links it to delivery of an updated gh0st RAT variant, while your analysts also observed clear preparation for follow-on payload execution even when the final stage was not fully visible in the sample.

Behavioral analysis is critical for catching RoningLoader early: Because the threat uses staged execution, security tool interference, and trusted process abuse, the clearest way to understand it is to observe the full chain in a sandbox and detect the behavior before the next payload gains a stronger foothold.

Observe RoningLoader detonated in the sandbox

RoningLoader RoningLoader fresh sample analysis in Interactive Sandbox

ANY.RUN’s Threat Intelligence Lookup is your pivot engine: By searching for RoningLoader process names, DLL artifacts, command-line strings, and behavioral patterns across millions of sandbox analyses, SOC and MSSP teams can identify related activity, expand detection coverage, and move from one alert to the broader intrusion chain faster.

Start your research with the threat name and browse sandbox analyses to watch behavior and gather indicators:

threatName:"roning"

RoningLoader RoningLoader sandbox analyses found in TI Lookup

What is RoningLoader Malware?

RoningLoader is a multi-stage Windows malware loader linked to a Dragon Breath campaign and publicly documented in 2025. Its role is not to create immediate visible damage on its own, but to quietly prepare an infected system for deeper compromise by helping attackers deliver and run additional malware while reducing the chance of early detection.

What makes RoningLoader notable is the way it blends into normal-looking system activity. Instead of behaving like a single obvious malicious file, it operates as part of a staged chain that helps attackers stay hidden, interfere with protections, and create safer conditions for the next payload to run. That makes it more dangerous than simple commodity malware, especially in environments that still rely heavily on static or signature-based detection.

Public reporting links RoningLoader to delivery of an updated gh0st RAT variant, which means the loader should be seen as an enabler of broader intrusion activity rather than the final objective. In practice, threats like this help attackers move from initial execution to longer-term access, surveillance, or follow-on malicious actions without exposing the full attack too early.

For businesses, the main concern is timing and visibility. A threat like RoningLoader can give attackers a head start by weakening defenses and hiding the transition to the next stage of the attack. That is why understanding the loader early matters: once the environment is prepared for follow-on malware, the incident becomes much harder to contain.

How RoningLoader Threatens Businesses and Organizations

RoningLoader increases risk by helping attackers move quietly from initial access to deeper compromise. Instead of acting as the final payload, it prepares the environment for what comes next and makes early detection harder.

Key risks include:

Reduced visibility early in the attack chain: Malicious activity can stay hidden while the next stage is prepared.

Security control interference: Attackers gain more room to operate before defenders see the full picture.

Follow-on payload delivery: The loader can help open the door to more serious malware and broader compromise.

Slower triage and investigation: Trusted system activity can make malicious behavior harder to recognize quickly.

Higher business impact: What starts as one infection can turn into a larger incident affecting operations, recovery time, and overall exposure.

The main danger with RoningLoader is not noise, but the quiet setup it gives attackers before the next stage begins.

Victimology: Which Industries Are Most at Risk?

RoningLoader activity was primarily aimed at Chinese-speaking users, with the malware delivered through trojanized installers impersonating trusted software such as Google Chrome and Microsoft Teams. The activity is linked to Dragon Breath, a threat actor associated with campaigns against Chinese-speaking targets, while broader reporting on the group connects it to activity involving the online gaming and gambling sectors.

That means the organizations most exposed are likely those with a mix of Windows-heavy environments, user-driven software installs, and limited early-stage behavioral visibility. The risk is especially relevant for:

Online gaming and gambling businesses: Dragon Breath has been linked to this broader ecosystem in prior reporting.

Organizations with Chinese-speaking user or employee bases: the campaign was reported as primarily targeting Chinese-speaking users.

Enterprises where users frequently download common software: trojanized installers work best in environments where trusted apps are often installed or updated.

Teams relying heavily on signature-based protection: RoningLoader’s staged, evasive behavior makes early detection harder without behavioral analysis.

Rather than targeting one sector as narrowly as some ransomware families do, RoningLoader appears more dangerous in environments where trusted software lures, user execution, and weak early visibility can help a staged loader operate before defenders recognize the full chain.

How Can Businesses Proactively Protect Against RoningLoader Malware

Threat Intelligence Lookup helps security teams search across millions of sandbox analyses using threat names, file names, command-line artifacts, and other behavioral indicators tied to RoningLoader. This makes it easier to find related samples, uncover activity patterns, and expand detection coverage beyond a single alert. RoningLoader’s staged execution and use of trusted Windows tools make this kind of pivoting especially useful.

threatName:"roning"

RoningLoader RoningLoader industries and submission countries revealed inside TI Lookup

Threat Intelligence Feeds deliver continuously updated machine-readable indicators into SIEM, EDR, SOAR, and other security tools, helping organizations block known malicious infrastructure and enrich detections faster. For a loader like RoningLoader, that means defenders can improve visibility into related activity and respond earlier in the attack chain.

RoningLoader TI Feeds providing 99% unique threat data

Behavior-based detection: Monitor for suspicious defense interference, abuse of legitimate Windows binaries, and unusual parent-child process chains. RoningLoader was documented using evasion methods and Defender tampering rather than relying on one obvious malicious action.

Application control and software validation: Restrict unapproved software installs and verify installers, since the campaign used trojanized software lures masquerading as trusted applications.

Least-privilege access: Limit unnecessary administrative rights so attackers have fewer opportunities to interfere with protections or move to more privileged stages. This is an inference from the reported abuse of high-privilege processes and security controls.

EDR hardening and monitoring: Make sure endpoint tools are configured to detect tampering attempts and suspicious abuse of native Windows components. Elastic reports the campaign targeted endpoint protections and used multiple evasive layers.

User awareness around software downloads: Train employees to avoid downloading installers from unofficial sources, especially when attackers impersonate well-known software brands to trigger execution.

How RoningLoader Gets in the System and Functions

RoningLoader’s operators do not appear to rely on one loud or obvious execution path. The malware is delivered through trojanized software installers disguised as trusted applications such as Google Chrome and Microsoft Teams, while the broader campaign was reported as primarily targeting Chinese-speaking users. That approach helps the infection begin under the cover of normal-looking software installation activity.

Once inside the system, RoningLoader’s goal is not immediate destruction, but quiet preparation for the next payload. Its main purpose is to weaken defenses, blend into legitimate Windows activity, and create safer conditions for follow-on malware to run with less visibility. The loader is linked to the delivery of an updated gh0st RAT variant.

RoningLoader’s execution flow can be broken into several distinct phases:

Phase 1: Trojanized Installation and Stage Launch

The infection begins with a fake installer that appears legitimate to the victim. For instance, the file may be launched through msiexec.exe, after which a secondary malicious component can start.

Phase 2: Payload Staging and Hidden Component Preparation

After launch, the malware prepares additional components needed for the rest of the chain. A dedicated directory is created and multiple files are dropped there, including a malicious DLL and an encrypted file used later in execution.

Phase 3: Defense Interference and Evasion

Before moving to the next payload, RoningLoader interferes with system protections. Research describes multiple evasion layers aimed at neutralizing endpoint security products, including PPL abuse, a legitimately signed driver, and custom WDAC policies used to interfere with Defender and evade Chinese EDR tools. This stage also included actions intended to weaken Windows protections and disrupt antivirus-related processes.

Phase 4: Trusted Process Abuse and Injection Preparation

RoningLoader then shifts toward execution under trusted system activity. Analysts observed the malware abusing legitimate Windows tools and preparing the next malicious component for injection into a high-privilege process.

Phase 5: Follow-On Payload Delivery

The final purpose of the chain is to launch the next malware stage, not to stop at the loader itself. RoningLoader was used to deploy an updated gh0st RAT variant, making the loader a bridge between the initial lure and deeper compromise.

Sandbox Analysis of RoningLoader Malware Sample

See full execution chain of RoningLoader

RoningLoader ANY.RUN sandbox revealing RoningLoader behavior in real time

The analyzed sample begins with 1.exe, which is launched as an MSI installer through msiexec.exe. After the installation environment is prepared, execution continues with a process named Snieoatwtregoable.exe, which acts as the next malicious stage in the chain.

RoningLoader Snieoatwtregoable.exe revealed inside ANY.RUN sandbox

This installer creates a new directory at C:\Program Files\Snieoatwtregoable. Inside it, two files are placed: a malicious DLL named Snieoatwtregoable.dll and an encrypted file called tp.png. From there, the malware initiates regsvr32.exe with the malicious DLL, using the process to carry out decryption and code injection.

At the same time, the malware interferes with Windows security mechanisms to make later stages more likely to succeed. A batch file named 1.bat disables User Account Control (UAC), reducing friction for malicious actions that follow. Another component, 1.dll, is copied to C:\Windows\System32\Wow64\Wow64Log.dll, allowing it to be loaded later by WOW64 processes. The malware also attempts to terminate a list of antivirus-related processes.

RoningLoader Windows Defender settings modified by the threat

The chain then moves deeper into defense tampering. regsvr32.exe repeatedly launches ClipUp.exe with a command line containing the -ppl parameter and the path C:\ProgramData\roming\MsMpEng.exe. These repeated executions are aimed at modifying Windows Defender-related components and weakening the platform’s protective mechanisms.

After interfering with antivirus protections, RoningLoader proceeds with its core loader function. For this stage, it uses the following command:

regsvr32.exe /S "C:\ProgramData\Roning\goldendays.dll"

RoningLoader Regsvr32.exe used to proceed with the core loader function

The purpose of this component is to inject the next payload into a legitimate, high-privilege system process in order to hide malicious activity behind trusted execution. To achieve this, RoningLoader first identifies a suitable target process. In the analyzed example, that process is TrustedInstaller.exe. The malware then reads the contents of C:\ProgramData\Roning\trustinstaller.bin and injects that payload into the target process.

RoningLoader ANY.RUN sandbox shows the injection of payload into the target process

Conclusion

RoningLoader is not loud, obvious malware. It is quiet, staged, and built to stay out of sight while preparing the next step of the attack. That is what makes it dangerous in environments where legitimate system activity can easily mask malicious behavior.

Defending against it requires more than tools. It requires context. And context is exactly what behavioral analysis and strong threat intelligence provide.

For businesses and security teams, the key lesson from RoningLoader is timing. The most effective defenses are the ones that work before or during the early stages of execution: behavior-based detection, proactive threat intelligence, and security controls that can spot trusted tool abuse before the next payload is delivered.

Use TI Lookup to start gathering actionable threat intelligence on the malware affecting your industry and region: Sign up to ANY.RUN

HAVE A LOOK AT

OnyxC2 screenshot
OnyxC2
onyxc2
OnyxC2 is a sophisticated Malware-as-a-Service platform sold on cybercrime forums that provides a turnkey solution for high-volume credential theft. The malware targets over 200 applications, scraping sensitive data from browsers, cryptocurrency wallets, and business-critical tools like FTP and email clients. It employs advanced evasion techniques, such as DLL sideloading and browser fingerprinting, to deliver encrypted payloads through legitimate signed binaries.
Read More
Neptune RAT screenshot
Neptune RAT is a Visual Basic .NET remote access trojan that gives attackers full control over infected Windows machines while stealing credentials from 270+ applications, hijacking cryptocurrency transactions, spying on victims in real time, and, in its most destructive mode, wiping the operating system entirely. Marketed openly on GitHub, Telegram, and YouTube as the "Most Advanced RAT," it is distributed under a malware-as-a-service model.
Read More
Phobos screenshot
Phobos
phobos ransomware
Phobos is a ransomware that locks or encrypts files to demand a ransom. It uses AES encryption with different extensions, which leaves no chance to recover the infected files.
Read More
Cobalt Strike screenshot
Cobalt Strike
cobaltstrike
Cobalt Strike is a legitimate penetration software toolkit developed by Forta. But its cracked versions are widely adopted by bad actors, who use it as a C2 system of choice for targeted attacks.
Read More
Backdoor screenshot
Backdoor
backdoor
A backdoor is a type of cybersecurity threat that allows attackers to secretly compromise a system and conduct malicious activities, such as stealing data and modifying files. Backdoors can be difficult to detect, as they often use legitimate system applications to evade defense mechanisms. Threat actors often utilize special malware, such as PlugX, to establish backdoors on target devices.
Read More
Gh0st RAT screenshot
Gh0st RAT
gh0st
Gh0st RAT is a malware with advanced trojan functionality that enables attackers to establish full control over the victim’s system. The spying capabilities of Gh0st RAT made it a go-to tool for numerous criminal groups in high-profile attacks against government and corporate organizations. The most common vector of attack involving this malware begins with spam and phishing emails.
Read More