Skip to content
Amaranth-Dragon Exploits WinRAR Vulnerability Against Southeast Asian Governments

Amaranth-Dragon Exploits WinRAR Vulnerability Against Southeast Asian Governments

First seen 5 Feb 2026, 18:32 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

The cyber threat group Amaranth-Dragon has leveraged a critical vulnerability in WinRAR, identified as CVE-2025-8088, to gain persistent control over systems belonging to Southeast Asian governments. This exploitation follows the vulnerability's addition to the CISA KEV list, indicating active exploitation in the wild.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 210d ago How this analysis works

More articles in this cluster (11)

Following this threat?

Track Amaranth-Dragon, Amaranth Loader and CVE-2025-8088 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed