logo

Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools

ID: f0c3aae2-c188-5edc-ab32-a0025e57fd0c

STIX ID: report--f0c3aae2-c188-5edc-ab32-a0025e57fd0c

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-08-27

Date Updated: 2026-08-27

Author: [email protected] (The Hacker News)

...
...

**Executive summary:** Acronis TRU observed a multi-stage campaign targeting Cambodian individuals and organizations that delivers the open-source Spark RAT via Inno Setup installers and DLL sideloading; the chain leverages BYOVD to install a vulnerable signed driver (ardrv.sys, CVE-2026-36425) to escalate privileges and neutralize security products, uses PNG-embedded shellcode and timing/anti-sandbox checks, and establishes persistence via services and scheduled tasks. The activity exhibits operational similarities to Silver Fox tactics but lacks sufficient evidence for definitive attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.