logo

China-Linked Amaranth-Dragon Exploits WinRAR Flaw in Espionage Campaigns

ID: bdb3e16f-5aa9-5a36-8740-a6aa1082969e

STIX ID: report--bdb3e16f-5aa9-5a36-8740-a6aa1082969e

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-02-04

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Threat actors linked to China—tracked as Amaranth-Dragon and tied to the APT41 ecosystem—conducted targeted espionage across Southeast Asia in 2025 by weaponizing CVE-2025-8088 in WinRAR and using malicious archives, DLL side-loading, and living-off-the-land techniques to deploy Havoc C2 and custom RATs (including TGAmaranth); separately, Mustang Panda used LNK-based lures and DLL search-order hijacking to deliver a PlugX variant (DOPLUGS) against diplomatic and policy targets, with campaigns showing high operational discipline, geo-restricted C2, and active exploitation of vulnerabilities and social-engineered lures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.