Story perspectives
China-Linked Cyber Espionage Targets Southeast Asia in 2025
2/5/2026
48 6
1 of 1
Story summary
- Amaranth-Dragon, linked to the China-affiliated APT 41 ecosystem, conducted targeted cyber espionage against government and law enforcement agencies across Southeast Asia in 2025.
- The campaigns exploited the WinRAR vulnerability Common Vulnerabilities and Exposures CVE-2025-8088 shortly after disclosure.
- They used tailored lures tied to local political events to increase engagement.
- Separately, Mustang Panda, a Chinese threat group, conducted a campaign using impersonation to deploy a PlugX variant, signaling ongoing regional threat activity.
