Amaranth Loader is a custom Windows first-stage loader used by the China-linked Amaranth-Dragon threat cluster in targeted cyberespionage operations. It retrieves an AES key from an external service, obtains an encrypted payload from a separate location, and decrypts and executes that payload directly in memory. Its principal observed follow-on payload is the Havoc command-and-control framework. The loader is launched through DLL side-loading using a legitimate executable, and its encrypted configuration and in-memory payload execution support defense evasion. It shares technical similarities with the APT41-associated tools DodgeBox, DUSTPAN, and DUSTTRAP.
Amaranth Loader has been deployed in campaigns targeting government and law enforcement organizations across Southeast Asia, including Cambodia, Thailand, Laos, Indonesia, Singapore, and the Philippines. Delivery chains have used cloud-hosted archives and politically themed lures aligned with local events. Earlier chains used ZIP archives containing shortcut files and batch scripts; later chains exploited the WinRAR path traversal vulnerability CVE-2025-8088 through crafted RAR archives. Exploitation enabled placement of launch components in the Windows Startup folder for persistence and subsequent execution. Associated delivery and command-and-control infrastructure used Cloudflare protection and geographic access restrictions to limit payload delivery to intended target countries. The campaigns emphasized sustained access and geopolitical intelligence collection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Multiple intrusion sets have been observed actively exploiting CVE-2025-8088, a path traversal vulnerability in WinRAR, to establish initial access and deploy modular malware frameworks. Affected software: WinRAR prior to version 7.13.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The archive contains several files, including a malicious DLL named Amaranth Loader that's launched by means of DLL side-loading... Once executed, the loader is designed to contact an external server to retrieve an encryption key, which is then used to decrypt an encrypted payload retrieved from a different URL and execute it directly in memory.
The archive contains several files, including a malicious DLL named Amaranth Loader that's launched by means of DLL side-loading... Once executed, the loader is designed to contact an external server to retrieve an encryption key, which is then used to decrypt an encrypted payload retrieved from a different URL and execute it directly in memory.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom loader used to deliver encrypted payloads in targeted campaigns; used as a staging component to deploy follow-on implants/C2 frameworks.
Previously unknown loader used by Amaranth-Dragon; delivered via malicious archives and uses DLL side-loading to decrypt and execute payloads (including in-memory execution of Havoc).
Custom first-stage loader deployed in campaigns exploiting WinRAR path traversal through crafted RAR archives. It uses an encrypted embedded configuration, resolves command-and-control endpoints at runtime, and loads subsequent payloads entirely in memory. The described infection chains use concealed payloads, DLL side-loading, and user-level persistence.
Malicious DLL loader delivered via spear-phishing lures and archive files; executed via DLL side-loading. It retrieves an encryption key from an external server, decrypts an encrypted payload from another URL, and executes it in-memory to deploy follow-on tooling (notably Havoc).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.