CVE Tools

Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools

The Hacker NewsBy The Hacker News

ResearchOPSWAT AppRemover

Our summary

Researchers at Acronis have identified a targeted cyber operation affecting individuals and organizations in Cambodia, centered on the deployment of the open-source Spark RAT. The multi-stage intrusion chain leverages the Bring Your Own Vulnerable Driver (BYOVD) technique, specifically exploiting a vulnerability in the OPSWAT AppRemover component ardrv.sys assigned as CVE-2026-36425">CVE-2026-36425. Attackers distribute phishing emails containing lures such as local government notices and health documents to deliver malicious archives that execute a signed Tencent binary.

Once executed, the malware employs DLL side-loading to escalate privileges and neutralize security software, including Microsoft Defender, Huorong Internet Security, and Tencent PC Manager. While the infrastructure shares tactical similarities with the Silver Fox threat actor group, particularly in the use of specific vulnerable drivers and persistence mechanisms, Acronis classifies this activity as an unattributed cluster due to a lack of definitive code or infrastructure overlap.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store