Cybersecurity threats in Cambodia have intensified with the emergence of a new campaign deploying Spark RAT, an open-source remote access trojan. Aimed at individuals and organizations, this threat utilizes a variety of deceptive tactics to infiltrate systems. The campaign was detailed in a recent analysis by Acronis Threat Research Unit, highlighting its sophisticated techniques.
Complex Attack Strategies
The attack leverages multiple strategies, including the ‘bring your own vulnerable driver’ (BYOVD) approach, to introduce a legitimate but vulnerable driver from OPSWAT AppRemover. This method allows attackers to escalate privileges and disable security measures. The campaign’s phishing emails distribute compressed files with Inno Setup executables, tricking recipients into executing them by mimicking official documents like government notices and real estate offers.
Once activated, the Inno Setup installer initiates a DLL side-loading process using a signed Tencent executable. This process delivers Spark RAT while employing timing-based checks to avoid sandbox detection, ensuring the malware remains undetected.
Security Software Evasion
To evade detection, the malware conducts checks for security processes, notably those of Huorong Internet Security. If detected, the malware attempts to compromise these defenses. The attack continues by decrypting shellcode hidden in PNG files, which the malware executes based on system privileges. It employs different modes, depending on the level of access, to inject shellcode into system processes like “vssvc.exe,” ensuring its persistence.
The campaign also installs the vulnerable “ardrv.sys” driver to disable key security processes. This strategy not only targets Microsoft Defender but also other security solutions, using additional embedded payloads to manage terminations in user mode.
Potential Connections to Silver Fox
The tactics used in this campaign share similarities with the Silver Fox threat actor, known for deploying ValleyRAT and other specialized payloads. Despite the overlaps, such as DLL sideloading and multi-stage delivery, no conclusive evidence links Spark RAT’s deployment to Silver Fox. The absence of shared infrastructure and unique malware signatures supports this distinction.
Researchers note that the configuration of Spark RAT includes elements suggesting Chinese-language development, aligning with several affected security products popular in Chinese-speaking regions. However, until more evidence emerges, the campaign remains unattributed, though parallels to the Silver Fox ecosystem persist.
As cybersecurity experts continue to monitor this threat, the importance of robust security measures and vigilance against phishing tactics cannot be overstated. Organizations are urged to strengthen defenses to mitigate risks posed by evolving cyber threats like Spark RAT.
