Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools

August 27, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Cambodian government and organizational entities
Incident: Deployment of Spark RAT using a BYOVD technique to disable security software.
Impact: Full system compromise and the neutralization of endpoint detection and response tools.
Attacker: Unidentified threat actors (possible Chinese-language links/Silver Fox ecosystem)
Analysis: The attack utilizes a multi-stage chain starting with phishing lures and an Inno Setup installer. It employs DLL side-loading via a signed Tencent executable and the ‘Bring Your Own Vulnerable Driver’ (BYOVD) technique to neutralize endpoint security. Once established, the Spark RAT provides the attacker with full remote control of the compromised system.
Recommendations: Implement strict policies to block the loading of known vulnerable drivers, specifically ardrv.sys.; Enhance monitoring for DLL side-loading activity involving signed third-party binaries.; Train employees to recognize phishing attempts using government or public health lures.
Source: The Hacker News / Acronis TRU

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *