Dangerous new malware takes advantage of WinRAR flaw: here’s what we know



  • Amaranth Dragon, linked to APT41, joins groups exploiting WinRAR CVE-2025-8088
  • Targets include organizations across Southeast Asia, using custom loaders and Cloudflare masquerading servers.
  • Vulnerability abused since mid-2025 by multiple state actors, with malware hidden through alternative data streams

We can now add Amaranth Dragon to the list of Chinese state-sponsored actors abusing the recently discovered WinRAR vulnerability.

Security researchers Check Point have reported attacks coming from this group, targeting organizations in Singapore, Thailand, Indonesia, Cambodia, Laos and the Philippines.



Leave a Comment

Your email address will not be published. Required fields are marked *