logo

New Amaranth Dragon cyberespionage group exploits WinRAR flaw

ID: ef6d610b-f580-51a7-a8a8-33b21ce278f5

STIX ID: report--ef6d610b-f580-51a7-a8a8-33b21ce278f5

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2026-02-04

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Check Point researchers attribute a targeted espionage campaign to an actor called Amaranth Dragon (linked to APT41) that has been actively exploiting WinRAR path-traversal CVE-2025-8088 since August 2025 to drop persistent loaders and deploy post-exploitation frameworks (Havoc) and a Telegram-based RAT (TGAmaranth) against government and law-enforcement targets across Southeast Asia; the attacks use ADS-based persistence, DLL sideloading, geofenced Cloudflare-hosted C2s, and include published IOCs and YARA rules—mitigation advice is to upgrade WinRAR to 7.13+ (latest 7.20).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.