Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools
- ID
- 18555
- Status
- summarized
- Published
- 27 Aug 2026, 7:00 PM
- Fetched
- 27 Aug 2026, 8:36 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/08/spark-rat-targets-cambodia-abuses.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 3.5
- Created
- 27 Aug 2026, 8:38 PM
- Tags
- Audience
- developers
What happened
A malware campaign targeting individuals and organizations in Cambodia delivers Spark RAT, an open-source Go-based remote access trojan, via phishing emails using lures like government notices and health materials. The attack uses a BYOVD technique loading a vulnerable OPSWAT driver (ardrv.sys) to escalate privileges and disable security tools, with anti-sandbox checks and DLL side-loading via a signed Tencent executable.
Why it matters
For builders operating in or serving Southeast Asian markets, this illustrates a real regional phishing-to-RAT playbook using BYOVD and DLL side-loading that could be adapted to target neighboring countries including Malaysia. If you run Windows infrastructure or develop installers in the region, review whether your endpoint protection can detect vulnerable driver loading and DLL side-loading chains.
Discussion angle
How BYOVD attacks work and whether Southeast Asian organizations should treat vulnerable signed driver abuse as a baseline threat model for endpoint defense.