logo

10 Days to Exploit: Amaranth-Dragon Weaponizes WinRAR Flaw to Spy on SE Asia

ID: 7582e594-2059-560a-9a2e-abff6dbcfd07

STIX ID: report--7582e594-2059-560a-9a2e-abff6dbcfd07

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-02-05

Date Updated: 2026-04-23

Author: Ddos

...
...

A Check Point Research report details a fast-moving Amaranth-Dragon espionage campaign that weaponized the WinRAR vulnerability CVE-2025-8088 within ten days of disclosure to deliver malicious RAR archives to government and law enforcement targets in Southeast Asia; the attackers used the vulnerability to drop startup scripts for persistence, deployed an Amaranth loader to fetch encrypted Havoc C2 payloads, and operated a Telegram-based RAT (TGAmaranth) to exfiltrate PII and issue remote commands while restricting C2 responses to targeted-country IPs to minimize detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.