Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Spark RAT Exploits Vulnerabilities to Target Cambodian Systems

Spark RAT Exploits Vulnerabilities to Target Cambodian Systems

Posted on August 27, 2026 By CWS

Cybersecurity threats in Cambodia have intensified with the emergence of a new campaign deploying Spark RAT, an open-source remote access trojan. Aimed at individuals and organizations, this threat utilizes a variety of deceptive tactics to infiltrate systems. The campaign was detailed in a recent analysis by Acronis Threat Research Unit, highlighting its sophisticated techniques.

Complex Attack Strategies

The attack leverages multiple strategies, including the ‘bring your own vulnerable driver’ (BYOVD) approach, to introduce a legitimate but vulnerable driver from OPSWAT AppRemover. This method allows attackers to escalate privileges and disable security measures. The campaign’s phishing emails distribute compressed files with Inno Setup executables, tricking recipients into executing them by mimicking official documents like government notices and real estate offers.

Once activated, the Inno Setup installer initiates a DLL side-loading process using a signed Tencent executable. This process delivers Spark RAT while employing timing-based checks to avoid sandbox detection, ensuring the malware remains undetected.

Security Software Evasion

To evade detection, the malware conducts checks for security processes, notably those of Huorong Internet Security. If detected, the malware attempts to compromise these defenses. The attack continues by decrypting shellcode hidden in PNG files, which the malware executes based on system privileges. It employs different modes, depending on the level of access, to inject shellcode into system processes like “vssvc.exe,” ensuring its persistence.

The campaign also installs the vulnerable “ardrv.sys” driver to disable key security processes. This strategy not only targets Microsoft Defender but also other security solutions, using additional embedded payloads to manage terminations in user mode.

Potential Connections to Silver Fox

The tactics used in this campaign share similarities with the Silver Fox threat actor, known for deploying ValleyRAT and other specialized payloads. Despite the overlaps, such as DLL sideloading and multi-stage delivery, no conclusive evidence links Spark RAT’s deployment to Silver Fox. The absence of shared infrastructure and unique malware signatures supports this distinction.

Researchers note that the configuration of Spark RAT includes elements suggesting Chinese-language development, aligning with several affected security products popular in Chinese-speaking regions. However, until more evidence emerges, the campaign remains unattributed, though parallels to the Silver Fox ecosystem persist.

As cybersecurity experts continue to monitor this threat, the importance of robust security measures and vigilance against phishing tactics cannot be overstated. Organizations are urged to strengthen defenses to mitigate risks posed by evolving cyber threats like Spark RAT.

The Hacker News Tags:Acronis, BYOVD, Cambodia, Cyberattack, Cybersecurity, malware attack, OPSWAT driver, remote access trojan, security vulnerabilities, Spark RAT

Post navigation

Previous Post: Critical Veeam ONE Flaw Risks Credential Exposure
Next Post: AI Agents Breach Hugging Face Through Improvised Message Board

Related Posts

Google Pixel 10 Adds C2PA Support to Verify AI-Generated Media Authenticity Google Pixel 10 Adds C2PA Support to Verify AI-Generated Media Authenticity The Hacker News
Malicious npm Packages Exploit PostCSS Tools for Windows RAT Malicious npm Packages Exploit PostCSS Tools for Windows RAT The Hacker News
Ghost Identities, Poisoned Accounts, & AI Agent Havoc Ghost Identities, Poisoned Accounts, & AI Agent Havoc The Hacker News
MuddyWater Deploys UDPGangster Backdoor in Targeted Turkey-Israel-Azerbaijan Campaign MuddyWater Deploys UDPGangster Backdoor in Targeted Turkey-Israel-Azerbaijan Campaign The Hacker News
Iranian Infy Hackers Reactivate C2 Servers After Internet Blackout Iranian Infy Hackers Reactivate C2 Servers After Internet Blackout The Hacker News
INTERPOL Dismantles 20,000+ Malicious IPs Linked to 69 Malware Variants in Operation Secure INTERPOL Dismantles 20,000+ Malicious IPs Linked to 69 Malware Variants in Operation Secure The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Nutex Health Data Breach: Critical Cybersecurity Incident
  • Australian Police Arrest Two in Major TeamPCP Cybercrime Case
  • Prepare Security Operations for AI-Driven Threats
  • AccuKnox Introduces AgentZ for AI Agent Management
  • AI Agents Breach Hugging Face Through Improvised Message Board

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Nutex Health Data Breach: Critical Cybersecurity Incident
  • Australian Police Arrest Two in Major TeamPCP Cybercrime Case
  • Prepare Security Operations for AI-Driven Threats
  • AccuKnox Introduces AgentZ for AI Agent Management
  • AI Agents Breach Hugging Face Through Improvised Message Board

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark