Cambodia RAT campaign weaponizes vulnerable driver to gut defenses

Acronis says a Cambodia-targeting campaign loads a vulnerable OPSWAT driver to kill security tools and drop Spark RAT.

CSBadmin
2 Min Read

A phishing wave aimed at Cambodia delivers Spark RAT, an open-source Go-based trojan, using lures built around government notices, public health alerts, real estate documents, and dental records, according to Acronis researchers.

Privilege escalation relies on the bring your own vulnerable driver (BYOVD) method. The loader pulls in ardrv.sys, a genuine OPSWAT AppRemover driver that is exploitable via CVE-2026-36425, then uses it to terminate security products including Microsoft Defender, Huorong Internet Security, and Tencent PC Manager.

Infection starts with a compressed archive containing an Inno Setup installer that triggers a DLL side-loading chain via a signed Tencent executable. The loader performs timing-based anti-sandbox checks, reviews running processes for the Huorong security product, and decrypts shellcode hidden inside PNG files that is injected into vssvc.exe or ctfmon.exe to deliver the RAT.

The payload patches AMSI and ETW functions, sets persistence through a Windows service or scheduled task, and re-injects its shellcode if the host process restarts. Acronis found malicious artifacts between late June and early August 2026 and said it is unclear whether the campaign is still active.

The activity shows operational similarities to the Silver Fox ecosystem, including DLL side-loading through signed applications and the targeting of Chinese-language security products, but Acronis assesses the link with low confidence because shared infrastructure, code reuse, and certificate matches are absent.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.