Amaranth Dragon: the Chinese group that exploited WinRAR vulnerabilities to target Asian governments

The cybersecurity threat landscape is continuously evolving, with increasingly sophisticated hacker groups targeting government organizations. In 2025, a new actor emerged on the cybersecurity scene, demonstrating how even widespread software like WinRAR can become the gateway for targeted attacks.

Amaranth Dragon, a cyber-espionage group linked to China (and associated with APT41), has conducted targeted campaigns against government agencies and law enforcement in several Southeast Asian countries, including Singapore, Thailand, Indonesia, Cambodia, Laos, and the Philippines. The attacks exploited a critical vulnerability in WinRAR (CVE-2025-8088), disclosed on August 8, 2025. The group began exploiting this flaw on August 18, 2025, just four days after a public exploit became available. The methodology involved using malicious RAR archives that exploited the path traversal vulnerability to write files to arbitrary locations using Windows Alternate Data Streams, achieving persistence by inserting malware into the startup folder. In early campaigns of 2025, the group also used ZIP archives with .LNK and .BAT files, while later variants employed TGAmaranth RAT with Telegram-based command and control.

These attacks are particularly significant because they demonstrate the speed with which threat actors can weaponize new vulnerabilities. The specific targeting of government agencies suggests geopolitical espionage objectives, with potential consequences for national security in affected countries. The use of sophisticated evasion techniques, such as cloud hosting (Dropbox) and Cloudflare-protected infrastructure with strict geofencing for target countries, highlights the advanced level of this threat.

To protect against similar threats, organizations and users should regularly update all software, including common applications like WinRAR, implement email security solutions to detect phishing attempts, adopt a multi-layered defense approach, and train personnel to recognize suspicious attachments. Applying access controls based on the principle of least privilege can also limit the impact of potential compromises.

  • Key points to remember:
  • Cyber-espionage attacks often exploit vulnerabilities in common and widely used software
  • The time between vulnerability disclosure and exploitation by attackers is drastically shrinking
  • A comprehensive security strategy requires timely updates, user training, and strict access controls

Sources:
BleepingComputer, The Hacker News, Cybersecurity News, Check Point Research, The CyberWire

Source: BleepingComputer