{
  "aliases": [
    "apt-q-27",
    "dragon breath",
    "golden eye dog"
  ],
  "attack_id": null,
  "attack_name": null,
  "attack_url": null,
  "counts": {
    "domain": 23,
    "ipv4": 5,
    "url": 1,
    "url_path": 5
  },
  "first_seen": {
    "domain": {
      "123.nsjdhmdjs.com": "2023-05-07",
      "2.nsjdhmdjs.com": "2023-05-07",
      "2.potatouu.com": "2023-05-07",
      "a.pic447.com": "2023-05-07",
      "ac2.nsjdhmdjs.com": "2023-05-07",
      "api.keensie.com": "2026-06-16",
      "d.pic447.com": "2023-05-07",
      "datareportnew.s3.ap-northeast-2.amazonaws.com": "2026-01-08",
      "goldeyeuu.io": "2026-01-08",
      "l.pic447.com": "2023-05-07",
      "l2.pic447.com": "2023-05-07",
      "links3s.s3.ap-east-1.amazonaws.com": "2026-01-18",
      "nsjdhmdjs.com": "2023-05-07",
      "potatouu.com": "2023-05-07",
      "s3work08.s3.ap-east-1.amazonaws.com": "2026-01-18",
      "t.pic447.com": "2023-05-07",
      "uu.goldeyeuu.io": "2026-01-08",
      "v.pic447.com": "2023-05-07",
      "v2.pic447.com": "2023-05-07",
      "w.pic447.com": "2023-05-07",
      "wk.goldeyeuu.io": "2026-01-08",
      "yy-service.s3.ap-northeast-2.amazonaws.com": "2026-04-07",
      "yyupdats.s3.ap-southeast-1.amazonaws.com": "2026-04-07"
    },
    "ipv4": {
      "143.92.57.46:15628": "2026-04-07",
      "185.135.79.196:5188": "2026-01-08",
      "185.135.79.200:5188": "2026-01-08",
      "206.233.128.103:443": "2023-05-07",
      "35.78.126.246:5198": "2026-06-16"
    },
    "url": {
      "http://206.233.128.103": "2023-05-07"
    },
    "url_path": {
      "/snapshothelper/Helper.dat": "2026-06-16",
      "/snapshothelper/SnapshotHelper.exe": "2026-06-16",
      "/snapshothelper/VideoNativeForViews.dll": "2026-06-16",
      "/snapshothelper/he.txt": "2026-06-16",
      "/snapshothelper/image.jpg": "2026-06-16"
    }
  },
  "first_seen_precision": {
    "domain": {},
    "ipv4": {},
    "url": {},
    "url_path": {}
  },
  "first_seen_range": {
    "earliest": "2023-05-07",
    "latest": "2026-06-16"
  },
  "generated_at": "2026-08-08T03:26:30+00:00",
  "indicators": {
    "domain": [
      "123.nsjdhmdjs.com",
      "2.nsjdhmdjs.com",
      "2.potatouu.com",
      "a.pic447.com",
      "ac2.nsjdhmdjs.com",
      "api.keensie.com",
      "d.pic447.com",
      "datareportnew.s3.ap-northeast-2.amazonaws.com",
      "goldeyeuu.io",
      "l.pic447.com",
      "l2.pic447.com",
      "links3s.s3.ap-east-1.amazonaws.com",
      "nsjdhmdjs.com",
      "potatouu.com",
      "s3work08.s3.ap-east-1.amazonaws.com",
      "t.pic447.com",
      "uu.goldeyeuu.io",
      "v.pic447.com",
      "v2.pic447.com",
      "w.pic447.com",
      "wk.goldeyeuu.io",
      "yy-service.s3.ap-northeast-2.amazonaws.com",
      "yyupdats.s3.ap-southeast-1.amazonaws.com"
    ],
    "ipv4": [
      "143.92.57.46:15628",
      "185.135.79.196:5188",
      "185.135.79.200:5188",
      "206.233.128.103:443",
      "35.78.126.246:5198"
    ],
    "url": [
      "http://206.233.128.103"
    ],
    "url_path": [
      "/snapshothelper/Helper.dat",
      "/snapshothelper/SnapshotHelper.exe",
      "/snapshothelper/VideoNativeForViews.dll",
      "/snapshothelper/he.txt",
      "/snapshothelper/image.jpg"
    ]
  },
  "last_modified": "2026-06-16T15:03:23+00:00",
  "maltrail_groups": [
    "Q27"
  ],
  "references": [
    "https://cyberpress.org/apt-q-27-evades-corporate-defenses/",
    "https://github.com/sophoslabs/IoCs/blob/master/double-dragon-breath-iocs.csv",
    "https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/",
    "https://tria.ge/260117-sjqyhafw7g/behavioral1",
    "https://www.virustotal.com/gui/file/0010762b4b1361aa9bc66892021869ff8cfa6ff51c660021843b5ad2b2799a8a/detection",
    "https://www.virustotal.com/gui/file/01268d68f1726a31e881515bd70139bf9e3e235fa3a899b0aa9e52db4a7c0547/detection",
    "https://www.virustotal.com/gui/file/14d374ea0604f70e6f39306efd948e7962fdd21cdb3e187ba461312027ebd3f5/detection",
    "https://www.virustotal.com/gui/file/873ea83b3507d8391b1b66f0f3d57cefff4307463b018eec09abbff601c83d30/detection",
    "https://www.virustotal.com/gui/file/b941c271b016f482137022b3da58e5aae4c989f37d351497e6f9a967dd6bfd20/detection",
    "https://x.com/WabiSabi777_/status/2009238999190392969",
    "https://x.com/askardyuss/status/2066859258130665974",
    "https://x.com/malwrhunterteam/status/1995568662284022243",
    "https://x.com/malwrhunterteam/status/2002322293091901684",
    "https://x.com/smica83/status/2012523844196544813"
  ],
  "related": [],
  "slug": "Q27",
  "timeline": [
    {
      "counts": {
        "domain": 1,
        "ipv4": 1,
        "url_path": 5
      },
      "first_seen": "2026-06-16",
      "indicators": {
        "domain": [
          "api.keensie.com"
        ],
        "ipv4": [
          "35.78.126.246:5198"
        ],
        "url_path": [
          "/snapshothelper/Helper.dat",
          "/snapshothelper/SnapshotHelper.exe",
          "/snapshothelper/VideoNativeForViews.dll",
          "/snapshothelper/he.txt",
          "/snapshothelper/image.jpg"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/askardyuss/status/2066859258130665974",
        "https://www.virustotal.com/gui/file/0010762b4b1361aa9bc66892021869ff8cfa6ff51c660021843b5ad2b2799a8a/detection"
      ],
      "total": 7
    },
    {
      "counts": {
        "domain": 2,
        "ipv4": 1
      },
      "first_seen": "2026-04-07",
      "indicators": {
        "domain": [
          "yy-service.s3.ap-northeast-2.amazonaws.com",
          "yyupdats.s3.ap-southeast-1.amazonaws.com"
        ],
        "ipv4": [
          "143.92.57.46:15628"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/malwrhunterteam/status/2002322293091901684",
        "https://cyberpress.org/apt-q-27-evades-corporate-defenses/",
        "https://www.virustotal.com/gui/file/14d374ea0604f70e6f39306efd948e7962fdd21cdb3e187ba461312027ebd3f5/detection"
      ],
      "total": 3
    },
    {
      "counts": {
        "domain": 2
      },
      "first_seen": "2026-01-18",
      "indicators": {
        "domain": [
          "links3s.s3.ap-east-1.amazonaws.com",
          "s3work08.s3.ap-east-1.amazonaws.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/smica83/status/2012523844196544813",
        "https://tria.ge/260117-sjqyhafw7g/behavioral1"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 3,
        "ipv4": 1
      },
      "first_seen": "2026-01-08",
      "indicators": {
        "domain": [
          "datareportnew.s3.ap-northeast-2.amazonaws.com",
          "goldeyeuu.io",
          "uu.goldeyeuu.io"
        ],
        "ipv4": [
          "185.135.79.196:5188"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/malwrhunterteam/status/1995568662284022243",
        "https://www.virustotal.com/gui/file/873ea83b3507d8391b1b66f0f3d57cefff4307463b018eec09abbff601c83d30/detection",
        "https://www.virustotal.com/gui/file/b941c271b016f482137022b3da58e5aae4c989f37d351497e6f9a967dd6bfd20/detection"
      ],
      "total": 4
    },
    {
      "counts": {
        "domain": 1,
        "ipv4": 1
      },
      "first_seen": "2026-01-08",
      "indicators": {
        "domain": [
          "wk.goldeyeuu.io"
        ],
        "ipv4": [
          "185.135.79.200:5188"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/WabiSabi777_/status/2009238999190392969",
        "https://www.virustotal.com/gui/file/01268d68f1726a31e881515bd70139bf9e3e235fa3a899b0aa9e52db4a7c0547/detection"
      ],
      "total": 2
    },
    {
      "counts": {
        "domain": 14,
        "ipv4": 1,
        "url": 1
      },
      "first_seen": "2023-05-07",
      "indicators": {
        "domain": [
          "123.nsjdhmdjs.com",
          "2.nsjdhmdjs.com",
          "2.potatouu.com",
          "a.pic447.com",
          "ac2.nsjdhmdjs.com",
          "d.pic447.com",
          "l.pic447.com",
          "l2.pic447.com",
          "nsjdhmdjs.com",
          "potatouu.com",
          "t.pic447.com",
          "v.pic447.com",
          "v2.pic447.com",
          "w.pic447.com"
        ],
        "ipv4": [
          "206.233.128.103:443"
        ],
        "url": [
          "http://206.233.128.103"
        ]
      },
      "precision": "exact",
      "references": [
        "https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/",
        "https://github.com/sophoslabs/IoCs/blob/master/double-dragon-breath-iocs.csv"
      ],
      "total": 16
    }
  ]
}
