Amaranth-Dragon Exploiting WinRAR Vulnerability to Gain Persistent to Victim Systems
ID: 9ff71ede-3164-5ef4-9dd2-26a690647e0a
STIX ID: report--9ff71ede-3164-5ef4-9dd2-26a690647e0a
Feed Name: cybersecurityNews.com
Amaranth-Dragon, a sophisticated espionage actor linked to APT-41, conducted targeted campaigns across Southeast Asia in 2025 by weaponizing WinRAR CVE-2025-8088 to perform path traversal and drop malicious startup scripts from crafted RAR archives; the attackers used an Amaranth Loader to retrieve encrypted payloads (often via services like Cloudflare) and deployed the Havoc Framework for persistent remote access and data exfiltration—organizations are urged to patch WinRAR immediately and monitor for malicious archives and unauthorized startup items.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
