Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign

Amaranth-Dragon public-sector espionage in Southeast Asia

Updated 04.02.2026 16:09
Case score 57
Members 1 First seen 04.02.2026 16:09 Latest activity 04.02.2026 16:09

Overview

Amaranth-Dragon ran tightly scoped espionage operations against government and law enforcement targets across Southeast Asia throughout 2025. The activity used malicious archives, country-specific lures, and infrastructure that only accepted connections from intended countries to limit exposure. In one intrusion chain, attackers abused **CVE-2025-8088** in **WinRAR**, used DLL side-loading to launch Amaranth Loader, and then deployed **Havoc** or the Telegram-based **TGAmaranth RAT**. CISA added **CVE-2025-8088** to the Known Exploited Vulnerabilities catalog, and the available evidence points to long-term persistence and covert intelligence collection rather than broad intrusion.
Latest development

Amaranth-Dragon disclosure links Southeast Asia espionage to APT 41

Check Point Research described Amaranth-Dragon as a previously undocumented China-linked cluster targeting government and law enforcement agencies across Southeast Asia throughout 2025, with campaigns tied to the APT 41 ecosystem, abuse of CVE-2025-8088 in RARLAB WinRAR, country-restricted Cloudflare-backed command-and-control, and payload delivery that included Havoc and TGAmaranth RAT through malicious RAR, ZIP, LNK, BAT, and DLL side-loading chains.

Signals

CVEs/products
Geographic context
Remediation
Status
Threat context

Threat actor context

3 listed

Malware & tooling context

3 families · 5 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Campaign Amaranth-Dragon Southeast Asia espionage campaign
Updated 04.02.2026 16:09 Lead Contribution 57
Objective Espionage Campaign Active Patch Patch Available

The **Amaranth-Dragon** espionage campaign targeted **government and law enforcement agencies** across **Southeast Asia** throughout **2025**, indicating a sustained effort to establish **long-term persistence** for **geopolitical intelligence collection**. The activity was narrowly scoped and tightly controlled to reduce exposure. Attack chains used country-specific lures and malicious archives to reach victims.