Campaign
Amaranth-Dragon public-sector espionage in Southeast Asia
Updated 04.02.2026 16:09
Case score 57
Why this score?
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 57
- Main story score
- 57
- Related evidence lift
- +0 / 20
- Contributing updates
- 0
- Context updates
- 0
Top contributors
- Campaign Lead campaign base score with no additional support members. main
Members 1
First seen 04.02.2026 16:09
Latest activity 04.02.2026 16:09
Overview
Amaranth-Dragon ran tightly scoped espionage operations against government and law enforcement targets across Southeast Asia throughout 2025. The activity used malicious archives, country-specific lures, and infrastructure that only accepted connections from intended countries to limit exposure.
In one intrusion chain, attackers abused **CVE-2025-8088** in **WinRAR**, used DLL side-loading to launch Amaranth Loader, and then deployed **Havoc** or the Telegram-based **TGAmaranth RAT**. CISA added **CVE-2025-8088** to the Known Exploited Vulnerabilities catalog, and the available evidence points to long-term persistence and covert intelligence collection rather than broad intrusion.
Latest development
Amaranth-Dragon disclosure links Southeast Asia espionage to APT 41
Check Point Research described Amaranth-Dragon as a previously undocumented China-linked cluster targeting government and law enforcement agencies across Southeast Asia throughout 2025, with campaigns tied to the APT 41 ecosystem, abuse of CVE-2025-8088 in RARLAB WinRAR, country-restricted Cloudflare-backed command-and-control, and payload delivery that included Havoc and TGAmaranth RAT through malicious RAR, ZIP, LNK, BAT, and DLL side-loading chains.
Amaranth-Dragon ran tightly scoped espionage operations against government and law enforcement targets across Southeast Asia throughout 2025. The activity used malicious archives, country-specific lures, and infrastructure that only accepted connections from intended countries to limit exposure. In one intrusion chain, attackers abused **CVE-2025-8088** in **WinRAR**, used DLL side-loading to launch Amaranth Loader, and then deployed **Havoc** or the Telegram-based **TGAmaranth RAT**.
Earlier and later variants used ZIP or password-protected RAR files, LNK and BAT components, cloud-hosted delivery, and tools such as **PowerShell** and **tar.exe**. The available evidence points to long-term persistence and covert intelligence collection rather than broad intrusion. CISA added **CVE-2025-8088** to the Known Exploited Vulnerabilities catalog on 2025-08-12 with a 2025-09-02 due date, so defenders need to verify **WinRAR** exposure, block malicious archive delivery, and look for side-loading and country-restricted command-and-control behavior.
Signals
CVEs/products
Geographic context
Remediation
Status
Threat context
Threat actor context
3 listedMalware & tooling context
3 families · 5 toolsTechnical intelligence
Existing Case dataMember happenings
Campaign
Amaranth-Dragon Southeast Asia espionage campaign
Objective
Espionage
Campaign
Active
Patch
Patch Available
Campaign
Amaranth-Dragon Southeast Asia espionage campaign
Objective
Espionage
Campaign
Active
Patch
Patch Available