Amaranth-Dragon Exploits WinRAR Vulnerability in Targeted Espionage Campaigns
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
Amaranth-Dragon, a cyber espionage group linked to China, has been attributed to a series of attacks against government and law enforcement agencies in Southeast Asia throughout 2025. Targeted countries include Cambodia, Thailand, Laos, Indonesia, Singapore, and the Philippines. The group exploits CVE-2025-8088, a vulnerability in WinRAR that allows for arbitrary code execution when malicious archives are opened. This exploitation was observed shortly after the vulnerability’s public disclosure in August 2025.
The attacks are highly controlled and narrowly focused, aiming to establish long-term persistence for geopolitical intelligence collection. Check Point Research noted that the campaigns often coincide with sensitive local political events, increasing the likelihood of engagement from targets. The attackers utilize spear-phishing emails to distribute malicious RAR files hosted on trusted cloud platforms like Dropbox, which helps them bypass traditional security measures.
Once executed, the malicious RAR file deploys a loader that retrieves an encryption key from an external server to decrypt and execute a payload directly in memory. The final payload includes the Havoc command-and-control framework. In earlier campaigns, the group used ZIP files containing Windows shortcuts and batch files to execute the loader, while a later campaign targeted Indonesia with a password-protected RAR archive delivering a remote access trojan (RAT) named TGAmaranth RAT.
The TGAmaranth RAT is equipped with commands for process listing, screenshot capture, command execution, and file transfers, showcasing the group’s technical maturity. The C2 infrastructure is secured by Cloudflare and configured to accept traffic only from specific target countries, further emphasizing the stealthy nature of these operations.
Amaranth-Dragon’s tactics and tools show strong similarities to those used by the APT41 group, indicating possible resource sharing or collaboration. The disciplined approach and operational patterns suggest a well-resourced team operating within the UTC+8 time zone, reinforcing the need for vigilance against such sophisticated threats.
Key Takeaways
- Regularly update WinRAR and other software to protect against known vulnerabilities like CVE-2025-8088.
- Be cautious with email attachments, especially from unknown sources, to avoid spear-phishing attacks.
- Implement advanced email filtering to detect and block suspicious attachments or links.
- Monitor network traffic for unusual patterns that may indicate a compromise.
- Educate employees about the risks of opening files from cloud storage services without verifying their source.
Key Terms & Concepts
- CVE-2025-8088: In this article, CVE-2025-8088 refers to a security vulnerability in WinRAR that allows arbitrary code execution when malicious archives are opened.
- Amaranth-Dragon: Amaranth-Dragon is a cyber espionage group linked to China, targeting government and law enforcement agencies in Southeast Asia.
- Havoc: Havoc is an open-source command-and-control framework used by threat actors to manage compromised systems.
- TGAmaranth RAT: TGAmaranth RAT is a remote access trojan used by Amaranth-Dragon to gain control over infected machines.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.