Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools
Researchers at Acronis have identified a targeted cyber operation affecting individuals and organizations in Cambodia, centered on the deployment of the open-source Spark RAT. The multi-stage intrusion chain leverages the Bring Your Own Vulnerable Driver (BYOVD) technique, specifically exploiting a vulnerability in the OPSWAT AppRemover component ardrv.sys assigned as CVE-2026-36425">CVE-2026-36425. Attackers distribute phishing emails containing lures such as local government notices and health documents to deliver malicious archives that execute a signed Tencent binary.
Once executed, the malware employs DLL side-loading to escalate privileges and neutralize security software, including Microsoft Defender, Huorong Internet Security, and Tencent PC Manager. While the infrastructure shares tactical similarities with the Silver Fox threat actor group, particularly in the use of specific vulnerable drivers and persistence mechanisms, Acronis classifies this activity as an unattributed cluster due to a lack of definitive code or infrastructure overlap.