logo

Amaranth-Dragon Exploiting WinRAR Vulnerability to Gain Persistent to Victim Systems

ID: 9ff71ede-3164-5ef4-9dd2-26a690647e0a

STIX ID: report--9ff71ede-3164-5ef4-9dd2-26a690647e0a

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-02-05

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Amaranth-Dragon, a sophisticated espionage actor linked to APT-41, conducted targeted campaigns across Southeast Asia in 2025 by weaponizing WinRAR CVE-2025-8088 to perform path traversal and drop malicious startup scripts from crafted RAR archives; the attackers used an Amaranth Loader to retrieve encrypted payloads (often via services like Cloudflare) and deployed the Havoc Framework for persistent remote access and data exfiltration—organizations are urged to patch WinRAR immediately and monitor for malicious archives and unauthorized startup items.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.