Amaranth-Dragon Exploits WinRAR Vulnerability for Persistent Access to Victim Systems
## Cybersecurity: Amaranth-Dragon Threat Overview
Cybersecurity: Amaranth-Dragon Threat Overview
A cyber-espionage group, named Amaranth-Dragon, has been identified as conducting targeted attacks against governmental and law enforcement entities in Southeast Asia throughout 2025. Evidence suggests a connection to APT-41, a known Chinese state-sponsored hacking group, due to shared tools and operational time zones (UTC+8).
Amaranth-Dragon employs a "path traversal" vulnerability in WinRAR, identified as CVE-2025-8088. This vulnerability allows the creation of malicious RAR archives that deposit files into restricted areas on a victim's computer without authorization. The group utilizes this to place a malicious script in the Windows Startup folder, ensuring persistent access by executing the malware upon system reboot.
Amaranth Loader: A custom tool used to "side-load" onto legitimate files, retrieving encrypted payloads from attacker-controlled servers. Havoc C2 Framework: Installed by the loader, this open-source command-and-control system allows remote management of infected devices. Cloudflare Geofencing: Servers are protected behind Cloudflare and configured to accept connections only from specific countries, such as Thailand and Indonesia, blocking other regions with a 403 error.
Evidence suggests a connection to APT-41, a known Chinese state-sponsored hacking group, due to shared tools and operational time zones (UTC+8).
In September 2025, a new remote access trojan, TGAmaranth RAT, was introduced. It uses Telegram bots for sending and receiving commands, disguising malicious traffic as normal chat application usage. This tool features advanced evasion capabilities against antivirus software and Endpoint Detection and Response (EDR) systems by unhooking security monitoring tools from system memory.
Amaranth-Dragon's sophisticated techniques, including the rapid adoption of vulnerabilities like CVE-2025-8088 and precise geopolitical targeting, have allowed them to compromise high-value targets effectively. The use of legitimate services such as Dropbox and Telegram further complicates tracking and mitigation efforts.
Based on reporting by GBHackers.
