Dangerous new malware exploits WinRAR flaw – here’s what we know



  • Amaranth Dragon, linked to APT41, joins groups exploiting WinRAR CVE-2025-8088
  • Targets include organizations across Southeast Asia, using custom loaders and Cloudflare-masked servers
  • Vulnerability abused since mid-2025 by multiple state actors, with malware hidden via Alternate Data Streams

We can now add Amaranth Dragon to the list of Chinese state-sponsored actors abusing the newly uncovered WinRAR vulnerability.

Security researchers Check Point said they saw attacks coming from this group, targeting organizations in Singapore, Thailand, Indonesia, Cambodia, Laos, and the Philippines.


https://cdn.mos.cms.futurecdn.net/X5DPDeFcG3TSkqdJMgSU3U-970-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img