Also known as: tracked as, Amaranth-Dragon targeted government, CVE-2026-3502, Aug 6, CVE-2025-15556, CVE-2025-8088, JadePuffer, from reconnaissance, fast16, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, StealthVector, DUSTTRAP, elections, mid-January 2026, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code
Amaranth-Dragon emerged as an untracked actor that has swiftly adopted tooling from the APT41 family to conduct state‑level espionage operations. Their first notable campaigns exploit the WinRAR CVE‑2025‑8088 path traversal vulnerability in milliseconds of its public disclosure, producing malicious RAR archives embedded in spearphishing emails directed at government agencies and defense contractors across Cambodia, Thailand, Laos, Indonesia, Singapore, and the Philippines. In addition to exploiting known CVEs, Amaranth-Dragon leverages a still‑undisclosed zero‑day vulnerability (CVE‑2026‑3502) in the TrueConf client via tampered update streams. This attack vector allows attackers to bypass normal update validations and deliver malicious code directly to users’ systems. The actor combines these tactics with sophisticated persistence, such as dropping .bat scripts into Startup folders or registry run keys, and uses disposable email addresses to stage phishing campaigns. The threat actor also routinely deploys backdoored container images (AWS AMI, GCP Image, Azure Image) and Docker containers to achieve persistent footholds in cloud environments. Their toolset includes a blend of custom malware and industry‑known ransomware like PlugX and WannaCry, coupled with legitimate utilities such as PowerShell, BITS, and rundll32 to facilitate execution and obfuscation. Operationally, Amaranth-Dragon demonstrates an ability to rapidly expand coverage across multiple countries while maintaining tight focus on one or two nations at a time. This pattern mirrors other APT41 operations, suggesting either a shared infrastructure pipeline or a formal partnership.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Amaranth-Dragon is a high‑profile threat actor closely linked to the China‑affiliated APT41 ecosystem that rapidly weaponized the WinRAR CVE‑2025‑8088 and the TrueConf client zero‑day CVE‑2026‑3502, delivering malicious payloads via spearphishing attachments to government, financial and critical infrastructure targets in Southeast Asia. The group demonstrates sophisticated delivery, persistence, and cloud‑based infrastructure abuse, enabling persistent access across multiple platforms.
Goals & Targeting
The group’s primary objective is espionage and information gathering for state actors aligned with China. By targeting government ministries, defense entities, financial services, media, critical infrastructure, maritime, healthcare, IT, and energy sectors—most notably in Southeast Asia and the United States—they aim to acquire strategic, technical, and economic intelligence. Their use of disposable email accounts and cloud persistence indicates a focus on long‑term surveillance rather than short burst attacks.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Amaranth‑Dragon’s campaigns exhibit an operational tempo of rapid weaponization and deployment—often launching new attacks within days of a CVE disclosure. Victims are predominantly state‑controlled entities in Southeast Asia, with occasional attacks on U.S. financial and defense sectors. The actor focuses on one or two countries simultaneously, maintaining localized spearphishing operations backed by disposable email accounts, while leveraging cloud images for persistence. Notable past operations include the use of backdoored WinRAR archives in late 2025 against Thai government ministries and the exploitation of TrueConf’s update mechanism to infiltrate Singaporean media firms.
IOC Patterns
Recommended Actions
No campaigns linked yet.
No observed data linked yet.
42
Techniques
48
Tools
0
Campaigns
54
IOCs
0
Observed Data
13
Tactics