- What: New campaign uses Spark RAT with BYOVD technique
- Impact: Targets individuals and organizations in Cambodia
Threat Intelligence New campaign targets Cambodia with Spark RAT using BYOVD technique August 28, 2026 Share By SC Staff (Adobe Stock) According to The Hacker News, a new cyber campaign is targeting individuals and organizations in Cambodia, distributing an open-source remote access trojan (RAT) known as Spark RAT. The attackers are employing sophisticated multi-stage infection chains and localized lures to ensnare victims, as described in a report by Acronis Threat Research Unit (TRU) researchers Darrel Virtusio and Subhajeet Singha. The campaign utilizes a "bring your own vulnerable driver" (BYOVD) technique, leveraging a legitimate but vulnerable driver (ardrv.sys) associated with OPSWAT AppRemover to escalate privileges and disable security software. Attackers distribute compressed archives containing an Inno Setup executable via phishing emails, using lures such as government notices, public health materials, and real estate documents relevant to Cambodia. The installer triggers a DLL side-loading chain using a signed Tencent executable, which then deploys the vulnerable driver and the Spark RAT payload. The RAT, written in Go, allows for remote control of compromised devices. The attack chain includes anti-sandbox checks and attempts to disable security products like Microsoft Defender and Huorong Internet Security. While exhibiting similarities to past Silver Fox threat actor activities, such as DLL sideloading and persistence mechanisms, definitive attribution is not yet established due to differences in payloads and lack of shared infrastructure. The presence of Chinese-language elements in the Spark RAT configuration suggests potential development or deployment links to Chinese-speaking environments. Source: The Hacker News SC Staff Related Threat Intelligence AI-powered investment fraud schemes targeting Gulf markets SC Staff August 28, 2026 Group-IB has identified two primary fraud models, GoldBull and CoinLure. Threat Intelligence Dark Caracal group enhances cyberespionage with new GoCaracal malware SC Staff August 27, 2026 Arctic Wolf researchers discovered GoCaracal during an investigation into a targeted intrusion in Venezuela. Threat Intelligence Nimbus Manticore expands infrastructure and malware arsenal SC Staff August 26, 2026 Nimbus Manticore, associated with the Tortoiseshell (Imperial Kitten) cluster, has been observed using an SSH-based tunneling utility and a C++ backdoor similar to its existing TWOSTROKE implant. Related Events Cybercast Better Threat Intelligence Between Public and Private Sectors On-Demand Event Virtual Conference Nationwide Cybersecurity Summit 2025: Safeguarding America’s Digital Future On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Account Harvesting Black Hat Deauthentication Attack Defacement Dictionary Attack Distributed Scans Domain Hijacking Fault Line Attacks Google Hacking Information Warfare You can skip this ad in 5 seconds