logo

China-linked Amaranth-Dragon hackers target Southeast Asian governments in 2025

ID: 4be3aff5-1c12-574b-8dcd-facd142ae85c

STIX ID: report--4be3aff5-1c12-574b-8dcd-facd142ae85c

Feed Name: Security Affairs

Threat Score
88/100

Date Published: 2026-02-05

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Check Point Research attributes a 2025 targeted cyber-espionage campaign in Southeast Asia to China-linked Amaranth-Dragon (linked to the APT41 ecosystem), which rapidly weaponized WinRAR path-traversal CVE-2025-8088 to deliver loaders and RATs (including a TGAmaranth RAT) via spear-phishing and malicious archives, employing DLL sideloading, in-memory Havoc C2, geo-restricted Cloudflare-protected infrastructure, and careful targeting of government and law-enforcement victims.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.