10 Days to Exploit: Amaranth-Dragon Weaponizes WinRAR Flaw to Spy on SE Asia
ID: 7582e594-2059-560a-9a2e-abff6dbcfd07
STIX ID: report--7582e594-2059-560a-9a2e-abff6dbcfd07
Feed Name: securityonline.info
A Check Point Research report details a fast-moving Amaranth-Dragon espionage campaign that weaponized the WinRAR vulnerability CVE-2025-8088 within ten days of disclosure to deliver malicious RAR archives to government and law enforcement targets in Southeast Asia; the attackers used the vulnerability to drop startup scripts for persistence, deployed an Amaranth loader to fetch encrypted Havoc C2 payloads, and operated a Telegram-based RAT (TGAmaranth) to exfiltrate PII and issue remote commands while restricting C2 responses to targeted-country IPs to minimize detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
