
Antonis Terefos

2026
The Amaranth-Dragon APT group campaigns targeted Southeast Asian governments, exploiting CVE-2025-8088, a path traversal vulnerability in WinRAR that was weaponized within ten days of public disclosure. These operations are notable for their precise alignment with regional geopolitical events, often using themed lures to increase success rates. Targets included police, coast guards, and foreign affairs ministries across Cambodia, Thailand, Laos, Indonesia, Singapore, and the Philippines, with lure documents referencing civil servant salary changes, joint military exercises, and national anniversary ceremonies, all timed to the day of real-world events.
Β The group used custom loaders, a Telegram-based RAT, the Havoc C2 framework, and geo-restricted infrastructure. The custom Amaranth Loader employed DLL sideloading, AES-CBC in-memory payload decryption, and evolved across campaigns from static key embedding to dynamic key retrieval, enabling the group to enforce country-level payload delivery, silently returning HTTP 403 to any IP outside the target nation. The Telegram-based RAT, TGAmaranth, introduced anti-debugging, anti-EDR via unhooked ntdll.dll injection from a suspended child process, and a full remote command set operated through a hardcoded Telegram bot token. The Havoc C2 Framework served as the post-exploitation backbone, delivered entirely in memory and protected behind Cloudflare.
Β The APT group's timely campaign operations ultimately exposed their operational timezone, cross-referencing compilation timestamps, archive metadata, and submission times consistently pointed to UTC+8, China Standard Time, further supporting their links to APT-41.
About Antonis Terefos
Antonis Terefos is a malware reverse engineer at Check Point with experience in the cyber threat landscape. He specializes in dissecting and analyzing malicious software to uncover hidden threats within the ever-evolving cyber threat landscape. In addition to his professional work, Antonis enjoys testing malware command-and-control (C2) infrastructures in his spare time. By exploring these C2 systems, he gains valuable insights into the strategies and tactics employed by threat actors, enriching his overall understanding of the adversarial landscape.
