Amaranth-Dragon Exploits WinRAR Vulnerability Against Southeast Asian Governments

Amaranth-Dragon Exploits WinRAR Vulnerability Against Southeast Asian Governments

First seen 5 Feb 2026, 18:32 UTC HelpnetsecurityHackreadPcmagHothardwareTechspot+6 32.3

Article Content

Browse articles
ThreatCluster

The cyber threat group Amaranth-Dragon has leveraged a critical vulnerability in WinRAR, identified as CVE-2025-8088, to gain persistent control over systems belonging to Southeast Asian governments. This exploitation follows the vulnerability's addition to the CISA KEV list, indicating active exploitation in the wild.