Amaranth-Dragon is an emerging threat actor linked to APT 41, targeting Southeast Asian entities.
Analyst brief
Amaranth-Dragon is a newly tracked threat actor likely linked to or part of the China-affiliated APT 41 ecosystem. It targets organizations in Cambodia, Thailand, Laos, Indonesia, Singapore, and the Philippines, typically focusing on one or two countries per campaign. The group shows technical maturity by quickly operationalizing CVE-2025-8088 in WinRAR after disclosure, with tooling and operational patterns overlapping with APT 41. Defenders should prioritize patching WinRAR and monitoring for suspicious spear-phishing activities aimed at Southeast Asian entities.
Amaranth-Dragon
unknown
Amaranth-Dragon is a previously untracked threat actor assessed to be closely linked to the China-affiliated APT 41 ecosystem, exhibiting similar tooling and operational patterns. The group demonstrated technical maturity by rapidly operationalizing CVE-2025-8088, a vulnerability in WinRAR, shortly after its public disclosure. Check Point Research has identified multiple campaigns targeting Cambodia, Thailand, Laos, Indonesia, Singapore, and the Philippines, with operations typically focused on one or two countries at a time. The overlaps in technical and operational indicators strongly suggest that Amaranth-Dragon is either affiliated with or part of the broader APT-41 ecosystem.
Amaranth-Dragon targets organizations in Cambodia, Thailand, Laos, Indonesia, Singapore, and the Philippines, typically focusing on one or two countries at a time.
Which vulnerability does Amaranth-Dragon exploit?+
Amaranth-Dragon quickly operationalizes CVE-2025-8088 in WinRAR after disclosure.