Amaranth-Dragon Exploiting WinRAR Vulnerability to Gain Persistent to Victim Systems
## Cybersecurity: WinRAR Vulnerability Exploitation by Amaranth-Dragon
Cybersecurity: WinRAR Vulnerability Exploitation by Amaranth-Dragon
A cyber-espionage group known as Amaranth-Dragon has executed targeted attacks against government and law enforcement agencies in Southeast Asia.
Throughout 2025, these campaigns have focused on geopolitical intelligence, aligning with significant political events in regions such as Thailand, Singapore, and the Philippines.
The group's strategy involves exploiting a critical vulnerability in the WinRAR compression software, identified as CVE-2025-8088. This path traversal flaw allows the execution of arbitrary code through malicious archive files.
By leveraging this vulnerability, attackers circumvent traditional security measures , gaining access to sensitive networks and converting standard administrative tools into vectors for system compromise.
Analysis by Check Point has identified overlaps between Amaranth-Dragon and APT-41, a group associated with Chinese state interests. Operating within the UTC+8 timezone, Amaranth-Dragon utilizes tools similar to those employed by APT-41, suggesting potential shared resources or direct links.
A cyber-espionage group known as Amaranth-Dragon has executed targeted attacks against government and law enforcement agencies in Southeast Asia.
The infection process typically begins with the distribution of weaponized RAR archives via spear-phishing emails. Once opened, the vulnerability enables the execution of a malicious script in the system's Startup folder, ensuring persistence without administrator privileges.
The attack is based on manipulating file paths within the RAR archive. The CVE-2025-8088 vulnerability fails to sanitize the destination path, allowing attackers to write files outside the intended folder.
CVE ID Affected Product Vulnerability Type Disclosure Date Impact
CVE-2025-8088 WinRAR (Windows Version) Path Traversal August 8, 2025 Arbitrary Code Execution: Allows remote attackers to drop files into sensitive directories by tricking a user into extracting a specially crafted archive file.
After compromise, attackers deploy the Amaranth Loader to retrieve encrypted payloads, ultimately aiming to deploy the Havoc Framework for persistent remote control and data exfiltration.
Organizations should prioritize patching the WinRAR vulnerability . Additionally, implementing monitoring for archive files with executable scripts and using endpoint protection systems can detect path traversal attempts and unauthorized startup items, preventing successful compromise.
Based on reporting by Cyber Security News.
