Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Amaranth-Dragon

Also known as: tracked as, Amaranth-Dragon targeted government, CVE-2026-3502, Aug 6, CVE-2025-15556, CVE-2025-8088, JadePuffer, from reconnaissance, fast16, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, StealthVector, DUSTTRAP, elections, mid-January 2026, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code

Description

Amaranth-Dragon emerged as an untracked actor that has swiftly adopted tooling from the APT41 family to conduct state‑level espionage operations. Their first notable campaigns exploit the WinRAR CVE‑2025‑8088 path traversal vulnerability in milliseconds of its public disclosure, producing malicious RAR archives embedded in spearphishing emails directed at government agencies and defense contractors across Cambodia, Thailand, Laos, Indonesia, Singapore, and the Philippines. In addition to exploiting known CVEs, Amaranth-Dragon leverages a still‑undisclosed zero‑day vulnerability (CVE‑2026‑3502) in the TrueConf client via tampered update streams. This attack vector allows attackers to bypass normal update validations and deliver malicious code directly to users’ systems. The actor combines these tactics with sophisticated persistence, such as dropping .bat scripts into Startup folders or registry run keys, and uses disposable email addresses to stage phishing campaigns. The threat actor also routinely deploys backdoored container images (AWS AMI, GCP Image, Azure Image) and Docker containers to achieve persistent footholds in cloud environments. Their toolset includes a blend of custom malware and industry‑known ransomware like PlugX and WannaCry, coupled with legitimate utilities such as PowerShell, BITS, and rundll32 to facilitate execution and obfuscation. Operationally, Amaranth-Dragon demonstrates an ability to rapidly expand coverage across multiple countries while maintaining tight focus on one or two nations at a time. This pattern mirrors other APT41 operations, suggesting either a shared infrastructure pipeline or a formal partnership.

Goals & Targeting

Targeted Sectors

Government
Financial services
Defense
Media
Critical infrastructure
Maritime
Healthcare
Information technology
Energy

Targeted Countries / Regions

CN
SG
PK
IN
US

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 8 hours ago

Executive Summary

Amaranth-Dragon is a high‑profile threat actor closely linked to the China‑affiliated APT41 ecosystem that rapidly weaponized the WinRAR CVE‑2025‑8088 and the TrueConf client zero‑day CVE‑2026‑3502, delivering malicious payloads via spearphishing attachments to government, financial and critical infrastructure targets in Southeast Asia. The group demonstrates sophisticated delivery, persistence, and cloud‑based infrastructure abuse, enabling persistent access across multiple platforms.

Goals & Targeting

The group’s primary objective is espionage and information gathering for state actors aligned with China. By targeting government ministries, defense entities, financial services, media, critical infrastructure, maritime, healthcare, IT, and energy sectors—most notably in Southeast Asia and the United States—they aim to acquire strategic, technical, and economic intelligence. Their use of disposable email accounts and cloud persistence indicates a focus on long‑term surveillance rather than short burst attacks.

Enhanced Description

Key Capabilities

  • Weaponizes CVE‑2025‑8088 (WinRAR) via malicious RAR archives
  • Exploits TrueConf client zero‑day CVE‑2026‑3502 through compromised update streams
  • Uses spearphishing attachments to deliver malicious payloads
  • Achieves persistence by dropping scripts/.bat files into Startup folders or registry run keys
  • Creates disposable email accounts for targeted phishing campaigns
  • Leverages free/trial services and cloud/container images (AWS AMI, GCP Image, Azure Image, Docker) for infrastructure and persistent access
  • Employs obfuscated code, metamorphic techniques, and diverse malware families such as PlugX and WannaCry

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Discovery
Collection
Command & Control
Exfiltration
Resource Development
Credential Access

ATT&CK Techniques

T1010
T1020
T1027
T1037
T1041
T1053
T1056
T1071
T1071.001
T1082
T1087
T1098
T1102
T1105
T1110
T1115
T1119
T1123
T1134
T1185
T1190
T1197
T1203
T1204.002
T1217
T1218
T1531
T1538
T1547
T1547.001
T1548
T1557
T1560
T1566.001
T1580
T1583
T1584
T1595
T1612
T1650
T1651
T1671

Software / Tooling

WinRAR
TrueConf client
AWS AMI
GCP Image
Azure Image
Docker
Havoc
DUSTTRAP
DUSTPAN
PlugX
WannaCry
PowerShell
netsh
Matrix
Hook
Nexus
Rogue
AdWind
Inter
fast16
Global
Handala
Process Hollowing
C2 infrastructure
AppDomainManager
Group Policy
Windows Command Shell
Telegram
GitHub
Remote access tools
curl
BITS
Rundll32
MSBuild

Campaigns & Victims

Amaranth‑Dragon’s campaigns exhibit an operational tempo of rapid weaponization and deployment—often launching new attacks within days of a CVE disclosure. Victims are predominantly state‑controlled entities in Southeast Asia, with occasional attacks on U.S. financial and defense sectors. The actor focuses on one or two countries simultaneously, maintaining localized spearphishing operations backed by disposable email accounts, while leveraging cloud images for persistence. Notable past operations include the use of backdoored WinRAR archives in late 2025 against Thai government ministries and the exploitation of TrueConf’s update mechanism to infiltrate Singaporean media firms.

IOC Patterns

  • Malicious RAR archive filenames
  • Exploitation of CVE‑2025‑8088 path traversal vulnerability
  • Exploitation of CVE‑2026‑3502 TrueConf updater abuse
  • .bat files placed in Startup folder for persistence
  • Spearphishing email attachments containing malicious RAR
  • Pattern of newly created disposable email accounts used for phishing campaigns
  • Suspicious use of cloud/container image registries with backdoored images
  • Use of free or trial services to set up infrastructure
  • Domains pointing to malicious servers
  • IP addresses used by command‑and‑control nodes
  • URLs linking to payloads or download stagers
  • SHA256 hash signatures for known malware binaries
  • MD5 hash signatures for known malware binaries

Recommended Actions

  • Apply emergency patches or workarounds for WinRAR CVE‑2025‑8088.
  • Patch or disable automatic updates for TrueConf client until vulnerability is fixed.
  • Block or filter suspicious RAR attachments in corporate email gateways.
  • Educate users on spearphishing risks and safe attachment handling practices.
  • Monitor and block malicious .bat scripts appearing in Startup folders.
  • Implement least privilege and restrict software update channels.
  • Deploy host‑based intrusion detection systems to spot known payloads.
  • Implement advanced email filtering, anti‑phishing controls with safe link checks for inbound emails.
  • Monitor organizational accounts for suspicious creation of new email or cloud service accounts and audit usage patterns.
  • Deploy image scanning solutions for container registries to detect malicious modifications in AMI/GCP/Azure images and Docker containers.
  • Patch all systems with the latest WinRAR updates promptly and disable legacy vulnerability features when possible.

ATT&CK Techniques

Privilege Escalation
1 technique
Reconnaissance
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

MD5 Hash 3 Filename 6 SHA-256 Hash 1 URL 1 IPv4 Address 5 Domain 4

References

  1. attack.mitre.org — Cited by web research for: services
  2. thehackernews.com — Cited by web research for: StealthVector
  3. research.checkpoint.com — Cited by web research for: T1203
  4. attack.mitre.org — Cited by web research for: Interception
  5. malpedia.caad.fkie.fraunhofer.de — Cited by web research for: curl
  6. research.checkpoint.com — Cited by web research for: C2 infrastructure
  7. blog.checkpoint.com — Cited by web research for: Healthcare

Intel Summary

42

Techniques

48

Tools

0

Campaigns

54

IOCs

0

Observed Data

13

Tactics

Tags

APT
China-affiliated
espionage
cybercrime
Southeast-Asia
WinRAR-exploitation

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.