HomeSecurityChinese hackers Amaranth-Dragon exploit WinRAR vulnerability

Chinese hackers Amaranth-Dragon exploit WinRAR vulnerability

Chinese hackers have been linked to cyberespionage targeting government and police agencies across Southeast Asiaduring 2025. Check Point Research is tracking the group under the alias Amaranth-Dragon and says it has connections to the APT41 ecosystem.

Amaranth-Dragon WinRAR

Targeted countries include Cambodia, Thailand, Laos, Indonesia, Singapore and the Philippines.

“Many of the campaigns coincided with sensitive local political developments, official government decisions , or regional security events,” the cybersecurity firm said in a report. The attackers tailored malicious activities to increase the likelihood that targets would interact with the content.

See also: Critical n8n vulnerability allows execution of system commands

The Israeli company added that the attacks were “focused” and “strictly defined.” It appears that the attackers sought to establish persistence for gathering geopolitical intelligence.

The most notable aspect of the threat actors' technique is the high degree of stealth, with the campaigns being "highly controlled" and the attack infrastructure being configured to only interact with victims in specific targeted countries (to minimize exposure).

Amaranth-Dragon: WinRAR vulnerability exploit

According to researchers, Chinese hackers Amaranth-Dragon exploited CVE-2025-8088, a now-patched security vulnerability affecting RARLAB WinRAR that allows arbitrary code execution when specially crafted files are opened by targets. The exploit of the vulnerability was observed approximately eight days after its public disclosure in August.

Chinese hackers Amaranth-Dragon exploit WinRAR vulnerability

“The group distributed a malicious RAR archive that exploits the CVE-2025-8088 vulnerability, allowing arbitrary code execution and persistence on the compromised computer,” Check Point researchers noted. “The speed and confidence with which this vulnerability was exploited underscores the technical maturity and preparedness of the group.”

See also: CISA adds SolarWinds WHD vulnerability to KEV List

Although the exact initial access agent remains unknown at this stage, the highly targeted nature of the campaigns, combined with the use of custom decoys related to political, economic or military developments in the region, suggests the use of spear-phishing emails to distribute archive files hosted on well-known cloud platforms such as Dropbox (to reduce suspicion and bypass traditional perimeter defenses).

The archive contains several files, including a malicious DLL, named Amaranth Loader, which is launched via DLL side-loading. The loader shares similarities with tools such as DodgeBox, DUSTPAN (also known as StealthVector), and DUSTTRAP, which have been linked to the APT41 hacking group.

Once executed, the loader contacts an external server to retrieve an encryption key, which is then used to decrypt an encrypted payload retrieved from a different URL. It is then executed directly in memory. The final payload, deployed as part of the attack, is the open-source C2 framework Havoc.

The first versions of the campaign, detected in March 2025, used ZIP files containing Windows shortcuts (LNK) and batch files (BAT) to decrypt and execute Amaranth Loader (using DLL side-loading). A similar attack sequence was also detected in a campaign in late October 2025 using decoys associated with the Philippine Coast Guard.

In another campaign targeting Indonesia in early September 2025, threat actors chose to distribute a RAR file from Dropbox to deliver a fully functional remote access Trojan (RAT) codenamed TGAmaranth RAT.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Docker fixes critical flaw in Ask Gordon AI

Chinese hackers Amaranth-Dragon exploit WinRAR vulnerability

Amaranth-Dragon's connections to APT41

Amaranth-Dragon’s connections to APT41 stem from overlaps in malware arsenal, suggesting a possible connection or shared resources between the two groups. It is worth noting that Chinese threat actors are known for sharing tools, techniques, and infrastructure.

"Furthermore, the development style, such as creating new threads within the export functions to execute malicious code, closely mirrors APT41's established practices," Check Point said.

«The compilation timestamps, campaign timing, and infrastructure management indicate a disciplined, well-equipped team operating in the UTC+8 (China Time) zone. Taken together, these technical and operational overlaps strongly suggest that Amaranth-Dragon is closely associated with or part of the APT41 ecosystem, continuing established patterns of targeting and deploying tools in the region».

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS