Dangerous new malware exploits WinRAR flaw – here’s what we know


  • Amaranth Dragon, linked to APT41, joins groups exploiting WinRAR CVE-2025-8088
  • Targets include organizations across Southeast Asia using custom loaders and Cloudflare masked servers
  • Vulnerability exploited since mid-2025 by multiple state actors with malware hidden via alternative data streams

We can now add Amaranth Dragon to the list of Chinese state-sponsored actors exploiting the recently uncovered WinRAR vulnerability.

Security researchers Check Point have reported attacks coming from this group targeting organizations in Singapore, Thailand, Indonesia, Cambodia, Laos and the Philippines.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top