Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign

Amaranth-Dragon public-sector espionage in Southeast Asia

Updated 04.02.2026 16:09
Case score 57
Case score 57 Members 1 Latest activity 04.02.2026 16:09
Members 1 First seen 04.02.2026 16:09 Last seen 04.02.2026 16:09 Updated 04.02.2026 16:09

Overview

Amaranth-Dragon ran tightly scoped espionage operations against government and law enforcement targets across Southeast Asia throughout 2025. The activity used malicious archives, country-specific lures, and infrastructure that only accepted connections from intended countries to limit exposure. In one intrusion chain, attackers abused **CVE-2025-8088** in **WinRAR**, used DLL side-loading to launch Amaranth Loader, and then deployed **Havoc** or the Telegram-based **TGAmaranth RAT**. CISA added **CVE-2025-8088** to the Known Exploited Vulnerabilities catalog, and the available evidence points to long-term persistence and covert intelligence collection rather than broad intrusion.