VMTech
Discuss a project

Spark RAT campaign in Cambodia disables defences with OPSWAT driver

Spark RAT campaign in Cambodia disables defences with OPSWAT driver

A campaign targeting individuals and organisations in Cambodia has deployed the open-source Spark RAT while abusing a vulnerable OPSWAT AppRemover driver, ardrv.sys, to neutralise security software. Acronis Threat Research Unit identified malicious artefacts from late June through early August 2026. The driver is vulnerable to CVE-2026-36425, and the activity is currently tracked as an unattributed cluster.

The attackers use phishing emails to distribute compressed archives. Their lures include Cambodian government notices, public-health materials, dental examination records, real-estate documents and promotional offers. Each archive contains an Inno Setup executable intended to persuade a recipient to start the infection chain.

Signed executable used for DLL sideloading

After execution, the installer triggers DLL sideloading through a signed Tencent executable. Interim payloads then deploy the vulnerable driver and prepare Spark RAT, a Go-based, cross-platform remote-access trojan that gives an operator remote control of a compromised device.

The DLL loader also performs a timing-based anti-sandbox check. It stops if sleep delays appear to have been shortened or manipulated. It inspects running processes for Huorong Internet Security's HipsTray.exe and attempts to weaken the product's privileges when it finds it.

A shellcode loader concealed in a PNG file checks whether it has SYSTEM privileges. When it does, it moves directly to injection; otherwise, it first establishes persistence. The payload decrypts further shellcode from another PNG and injects it into vssvc.exe. It monitors that process and reinjects the code if the process stops or restarts with a new process ID.

Multiple layers for evasion and persistence

In its setup path, the malware checks for hard-coded Qihoo 360 processes. If none are present, it creates Windows service-based persistence to relaunch the DLL-sideloading chain. The later stage can patch AMSI and ETW functionality, create a scheduled task, and install ardrv.sys to terminate security-related processes, including Microsoft Defender, Huorong Internet Security and Tencent PC Manager.

Another encrypted PNG payload performs user-mode termination of specified security processes. A fourth PNG-delivered payload injects shellcode into ctfmon.exe, culminating in Spark RAT execution. The repeated use of image files as containers adds concealment to an already multi-stage chain.

Silver Fox similarities do not establish attribution

Acronis noted references to drivers associated with TrueSight and Zemana Anti-Malware SDK, which Silver Fox has used before deploying Winos 4.0, also known as ValleyRAT. The campaign also resembles reported Silver Fox activity through overlapping targeting, signed-application sideloading, multi-stage delivery, Windows services and scheduled tasks, and Microsoft Defender exclusions.

However, Acronis found no shared infrastructure, function-level code reuse or matching certificates, and Spark RAT differs from the custom payloads usually associated with Silver Fox. The researchers therefore assess possible Chinese-language development or deployment links and operational similarities only with low confidence. For security teams, the practical implication is to block known vulnerable drivers, scrutinise DLL sideloading by signed applications, and investigate unexpected code injection into vssvc.exe or ctfmon.exe.

#cybersecurity#malware#windowssecurity#threatintel
Open analytics
On the site 2 views
min read 4 27.08.2026
Instagram

Spark RAT campaign in Cambodia disables defences with OPSWAT driver

Open the post on Instagram ↗