logo

Amaranth-Dragon: Weaponizing CVE-2025-8088 for Targeted Espionage in the Southeast Asia

ID: b9e58168-1e3e-5dc2-8175-e109d484cb43

STIX ID: report--b9e58168-1e3e-5dc2-8175-e109d484cb43

Feed Name: Check Point Research

Threat Score
90/100

Date Published: 2026-02-04

Date Updated: 2026-04-27

Author: [email protected]

...
...

**Check Point Research** documents the Amaranth-Dragon campaign—an APT-41‑linked, highly targeted cyber‑espionage operation across Southeast Asia in 2025 that rapidly weaponized a WinRAR path‑traversal vulnerability (CVE-2025-8088) to deliver a custom Amaranth Loader, Havoc C2 shellcode, and a Telegram‑controlled RAT (TGAmaranth), employing DLL sideloading, encrypted payloads, geo‑restricted C2, and numerous operational IoCs for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.