Spark RAT Campaign Exploits Vulnerable OPSWAT Driver to Bypass Security in Cambodia
A new Spark RAT campaign targeting Cambodia uses a vulnerable OPSWAT driver (ardrv.sys) via BYOVD techniques to bypass security tools, with multi-stage payloads involving phishing and DLL side-loading. The attack shows similarities to Silver Fox but lacks definitive attribution, though it employs open-source malware and targets Chinese-language security products.
Individuals and organizations in Cambodia have emerged as the target of a new campaign that delivers an open-source remote access trojan (RAT) called Spark RAT.
"The samples employ diverse lure themes, suggesting an effort to appeal to a broad range of potential victims. These include government notices, public health materials, real estate-related content, and other topics," Acronis Threat
*** END OF TRANSMISSION ***