China-linked Amaranth-Dragon hackers target Southeast Asian governments in 2025

3 Min Read

China-linked hackers tracked as Amaranth-Dragon targeted government and law enforcement agencies across Southeast Asia in 2025.

CheckPoint says China-linked threat actors, tracked as Amaranth-Dragon, carried out cyber-espionage campaigns in 2025 targeting government and law enforcement agencies across Southeast Asia.

- Advertisement -
China-linked Amaranth-Dragon hackers target Southeast Asian governments in 2025 | Philly PI

The activity is linked to the APT41 ecosystem and affected countries including Thailand, Indonesia, Singapore, and the Philippines.

“The attacks are performed by the Chinese group we track as Amaranth-Dragon. A previously unknown loader we call Amaranth Loader shares similarities with tools such as DodgeBox, Dustpan and Dusttrap associated with the Chinese hacking group known as APT-41 (FBI’s most wanted cybercriminal groups), suggesting a connection or shared resources between the groups.” reads the report published by CheckPoint.


What do you think? Post a comment.


The attacks were highly targeted and stealthy, aimed at long-term espionage rather than disruption. The threat actors limited their infrastructure to specific countries to avoid detection and moved quickly to exploit a newly disclosed WinRAR flaw (CVE-2025-8088).

- Advertisement -

EXPLORE MORE

Senate Blocks Report on Deaths of 9 Americans in the West Bank After Key 47–51 Vote

WASHINGTON, D.C. — In a 47–51 roll-call vote, the United States Senate…

Was Gloria Steinem a CIA agent working to overthrow the family?

Top feminist Gloria Steinem who died this week at age 92 may…

Apple fixed first actively exploited zero-day in 2026

Apple fixed an exploited zero-day in iOS, macOS, and other devices that…

USAF Approves FQ-42 & FQ-44 Collaborative Combat Aircraft

The U.S. Air Force has officially approved the General Atomics FQ-42 Vengeance…

The flaw CVE-2025-8088 was disclosed on August 8, 2025, with a public exploit released on August 14. Amaranth-Dragon began exploiting it days later, on August 18, 2025. The bug is a Windows WinRAR path-traversal issue that enables arbitrary code execution.

Victims were likely lured via spear-phishing emails with cloud-hosted malicious archives. Opening them triggered a loader using DLL side-loading, a tactic linked to APT41, which decrypted and ran the Havoc C2 framework entirely in memory.

Earlier campaigns used ZIP files with LNK and BAT scripts, while later ones targeted Indonesia with password-protected RARs delivering a TGAmaranth RAT controlled via a Telegram bot. The RAT supports process listing, screenshots, command execution, and file transfer. The C2 setup is hidden behind Cloudflare and restricted to specific countries, showing careful targeting and stealth.

Check Point Research found strong links between Amaranth-Dragon and APT-41. Both target government and law enforcement in Southeast Asia and use similar tools, including DLL sideloading, shared coding patterns, and UTC+8 operations, suggesting Amaranth-Dragon is part of the APT-41 ecosystem.

“The campaigns by Amaranth-Dragon exploiting the CVE-2025-8088 vulnerability highlight the recent trend of sophisticated threat actors rapidly weaponizing newly disclosed vulnerabilities. By leveraging a path traversal flaw in WinRAR, the group demonstrates its ability to adapt its tactics and infrastructure to maximize impact against highly targeted government and law enforcement organizations across Southeast Asian countries.” concludes the report. “The use of geo-restricted C&C servers, custom loaders, and open-source post-exploitation frameworks, such as Havoc, underscores the group’s technical proficiency and operational discipline. These attacks serve as a stark reminder of the importance of timely vulnerability management, user awareness, and robust defense-in-depth strategies. “

Pierluigi Paganini



Share This Article

China backs Cuba after Trump says island ‘will fall’

Beijing has vowed to support Havana against external interference…

Canada MAID Program: Truth About the 16,000 Assisted Deaths

A striking narrative has taken center stage in global…

US-Backed SDF Leader Joins Sharaa Regime As Presidential Advisor After Kurdish Force Dissolved

Via The Cradle Self-proclaimed Syrian President Ahmad al-Sharaa has…

Zionism and the Ottoman Empire: The Final Step to Conquering Palestine

The final step, which lasted until the fall of…

US Steps Up Africa Push As China Expands Economic, Security Footprint

Authored by Arthur Zhang via The Epoch Times, The…

The Iran War Has Turned VLCCs Into $650,000-A-Day Assets

Authored by Julianne Geiger via OilPrice.com, More Gulf oil…

Turkey Recruits Trump Insiders For New Washington Lobbying Push

Via Middle East Eye The Turkish government hired a lobbying firm…

CONVERSATION

Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted