Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign

Amaranth-Dragon public-sector espionage in Southeast Asia

Updated 04.02.2026 16:09
Case score 57
Case score 57 Members 1 Latest activity 04.02.2026 16:09
Patch available
Members 1 First seen 04.02.2026 16:09 Last seen 04.02.2026 16:09 Updated 04.02.2026 16:09

Overview

Amaranth-Dragon ran tightly scoped espionage operations against government and law enforcement targets across Southeast Asia throughout 2025. The activity used malicious archives, country-specific lures, and infrastructure that only accepted connections from intended countries to limit exposure. In one intrusion chain, attackers abused **CVE-2025-8088** in **WinRAR**, used DLL side-loading to launch Amaranth Loader, and then deployed **Havoc** or the Telegram-based **TGAmaranth RAT**. CISA added **CVE-2025-8088** to the Known Exploited Vulnerabilities catalog, and the available evidence points to long-term persistence and covert intelligence collection rather than broad intrusion.

Signals

6 derived
CVEs/products
CVE
Victims/regions
Sector government
Remediation
Remediation Patch available
Status
Campaign status Active
Threat context
Malware Tooling

Malware context

3 families · 5 tools
Tools
DodgeBox DUSTPAN DUSTTRAP Havoc StealthVector

Member happenings

1 related
Campaign Amaranth-Dragon Southeast Asia espionage campaign
Updated 04.02.2026 16:09 Lead Contribution 57
Objective Espionage Campaign Active Patch Patch Available

The **Amaranth-Dragon** espionage campaign targeted **government and law enforcement agencies** across **Southeast Asia** throughout **2025**, indicating a sustained effort to establish **long-term persistence** for **geopolitical intelligence collection**. The activity was narrowly scoped and tightly controlled to reduce exposure. Attack chains used country-specific lures and malicious archives to reach victims.