Amaranth Dragon Cyberespionage Group Exploits WinRAR CVE-2025-8088 Vulnerability
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
The newly identified Amaranth Dragon cyberespionage group is associated with state-sponsored operations from China and has been exploiting the CVE-2025-8088 vulnerability in WinRAR. This flaw allows attackers to write malicious files to arbitrary locations, leveraging the Alternate Data Streams feature in Windows. Since August 18, 2025, the group has utilized this vulnerability to deliver encrypted payloads to targeted organizations, primarily in Southeast Asia.
Researchers from Check Point have tracked Amaranth Dragon’s activities since March 2025, noting that the group has executed multiple campaigns, each focusing on one or two countries through strict geofencing. The attacks have been themed around geopolitical or local events to increase their effectiveness.
In earlier attacks, the group relied on ZIP archives containing .LNK and .BAT files to deploy their loader. Once the CVE-2025-8088 exploit became available, they shifted tactics to place malicious scripts in the Windows Startup folder, ensuring persistence by creating a Registry Run key.
The Amaranth Loader retrieves AES-encrypted payloads from command-and-control servers, often utilizing the Havoc C2 post-exploitation framework, which has been in use since at least 2023. The group has also deployed a new remote access tool, TGAmaranth RAT, which utilizes a Telegram bot for command-and-control activities.
Amaranth Dragon’s technical proficiency is evident in their ability to adapt tactics and infrastructure for maximum impact. Their use of Cloudflare infrastructure to filter traffic from non-target countries demonstrates a sophisticated approach to evading detection.
Given the ongoing exploitation of CVE-2025-8088 by various threat actors, organizations are strongly advised to upgrade to WinRAR version 7.13 or later, as this version addresses the vulnerability. The widespread nature of these attacks highlights the critical need for vigilance in cybersecurity practices.
Why This Matters for Your Security
The activities of Amaranth Dragon reveal significant risks for organizations in Southeast Asia, particularly those in government and law enforcement sectors. Their targeted approach and use of advanced techniques underscore the importance of maintaining updated software and monitoring for unusual activity.
Organizations should be aware of the tactics employed by Amaranth Dragon, such as the use of geopolitical themes in phishing attempts, which could manifest in emails or messages that appear relevant to current events. This highlights the need for training staff to recognize such lures.
Furthermore, the deployment of tools like TGAmaranth RAT indicates that organizations must enhance their endpoint security measures to detect and respond to sophisticated malware that can evade traditional defenses.
- Amaranth Dragon: A cyberespionage group linked to APT41, exploiting vulnerabilities for targeted attacks.
- CVE-2025-8088: A vulnerability in WinRAR that allows malicious file writing via Alternate Data Streams.
- Havoc C2: A post-exploitation framework used by Amaranth Dragon for command-and-control operations.
- TGAmaranth RAT: A new remote access tool deployed by Amaranth Dragon, utilizing Telegram for C2.
- Cloudflare: Infrastructure used by Amaranth Dragon to filter traffic and enhance stealth in their operations.
Key Takeaways
- Upgrade to WinRAR version 7.13 or later to mitigate the CVE-2025-8088 vulnerability.
- Implement training for staff to recognize phishing attempts themed around current geopolitical events.
- Enhance endpoint security measures to detect advanced malware like TGAmaranth RAT.
- Regularly monitor network traffic for unusual patterns that may indicate a cyber intrusion.
- Establish a response plan for potential cyberattacks, including incident detection and recovery protocols.
Key Terms & Concepts
- CVE-2025-8088: In this article, CVE-2025-8088 refers to a vulnerability in WinRAR that allows attackers to write malicious files to arbitrary locations.
- Amaranth Dragon: Amaranth Dragon is a cyberespionage group linked to state-sponsored operations from China, targeting government and law enforcement agencies.
- TGAmaranth RAT: TGAmaranth RAT is a remote access tool used by Amaranth Dragon for command-and-control activities, utilizing Telegram for communication.
- Havoc C2: Havoc C2 is a post-exploitation framework that has been used in cyberattacks since at least 2023, including by Amaranth Dragon.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.