{"id":2564,"date":"2026-08-27T11:32:15","date_gmt":"2026-08-27T11:32:15","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2564"},"modified":"2026-08-27T11:32:15","modified_gmt":"2026-08-27T11:32:15","slug":"spark-rat-targets-cambodia-abuses-vulnerable-opswat-driver-to-disable-security-tools","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2564","title":{"rendered":"Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgvqqkrFYi_Np3w-hHvDbFZqWnf1qCrkS6zwJARAyiKX99YdH2w37pqvD-Zy1HPAYdbJbFu3Tztap9lcuv-lkq8wd9elTkfK0NWN5a9J8218OE9btcQHMdyM93GiuYLuj5mC_TPFBXnVZkUEckgARKceSsJKRqHDeW-U_tsDcPscO3-s2Oid28OEZTz7cIw\/s1700-e365\/combo-malware.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Individuals and organizations in Cambodia have emerged as the target of a new campaign that delivers an open-source remote access trojan (RAT) called <strong>Spark RAT<\/strong>.<\/p>\n<p>\u00abThe samples employ diverse lure themes, suggesting an effort to appeal to a broad range of potential victims. These include government notices, public health materials, real estate-related content, and other topics,\u00bb Acronis Threat Research Unit (TRU) researchers Darrel Virtusio and Subhajeet Singha <a href=\"https:\/\/www.acronis.com\/en\/tru\/posts\/cambodia-focused-cluster-uses-multi-stage-infection-chain-with-localized-lures\/\" target=\"_blank\">said<\/a> in an analysis published Wednesday.<\/p>\n<p>The multi-stage attack is notable for employing the bring your own vulnerable driver (BYOVD) technique to load a legitimate-but-vulnerable driver associated with OPSWAT AppRemover (\u00abardrv.sys\u00bb) to escalate privileges and neutralize security software.<\/p>\n<p>Attack chains likely make use of targeting phishing emails to distribute compressed archives containing an Inno Setup executable and trick recipients into running it using wide-ranging lures, including Cambodian government notices, public health announcements, dental examination records, real estate documents, and promotional offers.<\/p>\n<p>Acronis said it discovered a number of malicious artifacts between late June through early August 2026, although it&#8217;s unclear if the campaign remains ongoing.<\/p>\n<p>The Inno Setup installer is designed to trigger a DLL side-loading chain using a signed Tencent executable, which then delivers interim payloads responsible for deploying the vulnerable \u00abardrv.sys\u00bb and then launching the Spark RAT payload. Spark RAT is an <a href=\"https:\/\/github.com\/XZB-1248\/Spark\" target=\"_blank\">open-source, Go-based cross-platform RAT<\/a> that enables remote control of compromised devices.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/zero-trust-claude-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj8iAp2j8rqTq6aptj6yiYHC-B73UxnWI2NQMt0azp6OVLq9JkO8cpYokLWa8t_IKqrHKPsaM5D_lQ9Ip7kZTi3at4oYfzN1m1b_T4b6MuzBWtmlhdLcQ0nZHicD94rliREFDRewsKBQCTYrAAVNzYKj84_0EZskDUxvkc972s9fYAqcQGEQjVZTc0cr7TB\/s728-e100\/ThreatLocker-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The DLL loader also carries out a timing-based anti-sandbox check to detect environments that shorten or manipulate sleep delays, and proceeds to terminate execution if the elapsed time falls outside the expected range. Furthermore, it reviews running processes for those related to Huorong Internet Security (\u00abHipsTray.exe\u00bb), a Chinese endpoint security program.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>If the process is present, the loader attempts to weaken the privileges of the security product. In the next stage, it decrypts shellcode concealed within a PNG file present in the archive to run a second stager, which verifies if it is running with SYSTEM privileges.<\/p>\n<p>\u00abBased on these checks, the payload selects one of two execution modes,\u00bb Acronis said. \u00abIf it is already running as SYSTEM, it proceeds directly to inject mode, bypassing the persistence setup and executing the next stage. Otherwise, it enters setup mode, where it establishes persistence first, then executes the next stage.\u00bb<\/p>\n<p>The inject mode works by parsing and decrypting shellcode embedded in another PNG file from the archive, and then injecting it into \u00abvssvc.exe\u00bb and executing it within the context of the target process. To ensure the injected payload remains running, it monitors the \u00abvssvc.exe\u00bb instance and re-injects the shellcode if the process terminates or restarts with a new PID.<\/p>\n<p>In the setup mode, the malware reads and decrypts the shellcode from the same file, after which it checks for a list of hard-coded processes associated with Qihoo 360. If none of them are found, it sets up a Windows service-based persistence mechanism to launch the binary that sideloads the DLL to relaunch the entire cycle all over again. After establishing persistence on the host, it injects the shellcode into \u00abvssvc.exe\u00bb like before.<\/p>\n<p>The payload performs the following sequence of actions &#8211;<\/p>\n<ul>\n<li>Attempt to patch AMSI and ETW related functionality<\/li>\n<li>Setup persistence using a scheduled task<\/li>\n<li>Install the ardrv.sys driver that&#8217;s vulnerable to CVE-2026-36425 to terminate security-related processes such as Microsoft Defender, Huorong Internet Security, and Tencent PC Manager<\/li>\n<li>Read and decrypt another embedded payload from a third PNG file to perform user-mode termination of hard-coded security processes<\/li>\n<\/ul>\n<p>Simultaneously, a fourth PNG-based payload file is processed to extract and decrypt shellcode that&#8217;s injected into \u00abctfmon.exe,\u00bb ultimately leading to the execution of Spark RAT.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/corelight-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuvAqH13TTYyJD3aI-pJcYl54BoxQWMHc2aFwW2HbYUa5IKCjvHlzpzkFwXLTuV8aytky8kqLBgkoOtC8VQM5CGR0N5BXBl8RSXl-PYx_vIPbiLywiqXIvTPmm18cdEm_C0heVB-3U8zfG7K27RCAurtJ7OvxEyfQ0sVV_RRx1N4ZMWkqKgEBmkcDgjD6I\/s728-e100\/code-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Interestingly, the BYOVD routine references a number of other drivers, including those part of TrueSight and Zemana Anti-Malware SDK, both of which have been put to use by the Silver Fox threat actor prior to dropping Winos 4.0 (aka ValleyRAT). In addition, the targeting of Huorong security processes has been repeatedly observed in past Silver Fox-related attacks.<\/p>\n<p>Other Silver Fox-style indicators include targeting overlaps, the use of DLL sideloading through a signed application, multi-stage payload delivery, persistence through Windows services and scheduled tasks, and Microsoft Defender exclusions. Despite these similarities, there is not enough evidence to definitively attribute the latest activity to the threat actor.<\/p>\n<p>This assessment, Acronis said, is based on the absence of shared infrastructure, function-level code reuse, and matching certificates. Another crucial differentiator is the choice of the malware itself. While Silver Fox campaigns are known to leverage ValleyRAT and other custom payloads, it has not been attributed to the deployment of an open-source RAT.<\/p>\n<p>\u00abThis difference does not rule out a relationship, since operators can change payloads, but it removes one of the stronger links used in previous attributions,\u00bb the cybersecurity company added. \u00abThe Spark RAT configuration contains a Chinese-language value, and the malware targets several security products commonly used in Chinese-speaking environments.\u00bb<\/p>\n<p>\u00abWe therefore track the activity as an unattributed cluster with possible Chinese-language development or deployment links and operational similarities to the broader Silver Fox ecosystem. This assessment remains low confidence and may change if additional code, infrastructure, victimology, or other attributional evidence is identified.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Individuals and organizations in Cambodia have emerged as the target of a new campaign that delivers an open-source remote access trojan (RAT) called Spark RAT. \u00abThe samples employ diverse lure&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2565,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[226,3201,772,865,3202,264,47,3200,78,261,770],"class_list":["post-2564","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-abuses","tag-cambodia","tag-disable","tag-driver","tag-opswat","tag-rat","tag-security","tag-spark","tag-targets","tag-tools","tag-vulnerable"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2564","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2564"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2564\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2565"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2564"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2564"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2564"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}