Check Point Research attributed a set of tightly scoped cyber-espionage campaigns against government and law enforcement organizations in Southeast Asia to a China-linked activity cluster it tracks as Amaranth-Dragon, assessed as connected to the broader APT41 ecosystem. Targeting was reported across Cambodia, Thailand, Laos, Indonesia, Singapore, and the Philippines, with lures aligned to local geopolitical events and infrastructure configured for stealth, including geofencing so command-and-control only interacted with victims in specific countries. The intrusion chain evolved over 2025, and—shortly after public disclosure—began weaponizing the WinRAR vulnerability CVE-2025-8088 via malicious RAR archives to achieve code execution and persistence.
Reporting describes Amaranth-Dragon using a custom Amaranth Loader to deliver encrypted payloads, with C2 infrastructure shielded behind Cloudflare and use of legitimate services (e.g., Dropbox) to stage content; Check Point also documented deployment of the Havoc C2 framework and a newly tracked TGAmaranth RAT that uses Telegram bot-based C2 and includes anti-EDR/anti-AV features. Separate coverage notes CVE-2025-8088’s exploitation mechanics (including abuse of Windows Alternate Data Streams (ADS) to write to arbitrary locations such as Startup paths) and that multiple other threat groups have also exploited the flaw, underscoring ongoing operational risk beyond this single actor.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
On February 4, 2026, Check Point Research published its findings on Amaranth-Dragon, detailing the 2025 Southeast Asia espionage campaigns, rapid exploitation of CVE-2025-8088, use of Amaranth Loader and Havoc C2, and the TGAmaranth RAT. The report also highlighted Cloudflare-fronted, geo-fenced infrastructure and assessed links to the APT41 ecosystem.
In a later 2025 campaign focused on Indonesia, the group delivered a newly documented malware family called TGAmaranth RAT using password-protected RAR files, sometimes hosted on Dropbox. The RAT used a Telegram bot for command-and-control and included anti-debugging and anti-EDR/AV features.
Less than ten days after CVE-2025-8088 became public, Amaranth-Dragon incorporated malicious RAR archives exploiting the flaw into its espionage operations. The exploit allowed the attackers to drop scripts into the Windows Startup folder and sometimes add Registry Run keys for persistence.
The WinRAR Windows path traversal vulnerability CVE-2025-8088 was publicly disclosed on August 8, 2025. Public exploit availability enabled threat actors to begin weaponizing the flaw for malicious archive-based intrusion chains.
Before adopting the WinRAR exploit, Amaranth-Dragon used ZIP archives containing .LNK and .BAT files to decrypt and execute its custom Amaranth Loader. The loader then fetched encrypted payloads from command-and-control infrastructure, often leading to in-memory deployment of Havoc C2.
Throughout 2025, the China-linked cluster tracked as Amaranth-Dragon targeted government and law-enforcement organizations in Southeast Asia using lures tied to local political and geopolitical events. The activity was later assessed as closely linked to, or part of, the APT41 ecosystem based on tooling, tradecraft, and operational indicators.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcecybersecuritynews.com
Open sourcesecurityonline.info
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourceresearch.checkpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.