Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools
ID: f0c3aae2-c188-5edc-ab32-a0025e57fd0c
STIX ID: report--f0c3aae2-c188-5edc-ab32-a0025e57fd0c
Feed Name: The Hacker News
**Executive summary:** Acronis TRU observed a multi-stage campaign targeting Cambodian individuals and organizations that delivers the open-source Spark RAT via Inno Setup installers and DLL sideloading; the chain leverages BYOVD to install a vulnerable signed driver (ardrv.sys, CVE-2026-36425) to escalate privileges and neutralize security products, uses PNG-embedded shellcode and timing/anti-sandbox checks, and establishes persistence via services and scheduled tasks. The activity exhibits operational similarities to Silver Fox tactics but lacks sufficient evidence for definitive attribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
