China-linked Amaranth-Dragon hackers target Southeast Asian governments in 2025
ID: 4be3aff5-1c12-574b-8dcd-facd142ae85c
STIX ID: report--4be3aff5-1c12-574b-8dcd-facd142ae85c
Feed Name: Security Affairs
Threat Score
Check Point Research attributes a 2025 targeted cyber-espionage campaign in Southeast Asia to China-linked Amaranth-Dragon (linked to the APT41 ecosystem), which rapidly weaponized WinRAR path-traversal CVE-2025-8088 to deliver loaders and RATs (including a TGAmaranth RAT) via spear-phishing and malicious archives, employing DLL sideloading, in-memory Havoc C2, geo-restricted Cloudflare-protected infrastructure, and careful targeting of government and law-enforcement victims.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
