According to The Hacker News, a new cyber campaign is targeting individuals and organizations in Cambodia, distributing an open-source remote access trojan (RAT) known as Spark RAT. The attackers are employing sophisticated multi-stage infection chains and localized lures to ensnare victims, as described in a report by Acronis Threat Research Unit (TRU) researchers Darrel Virtusio and Subhajeet Singha.The campaign utilizes a "bring your own vulnerable driver" (BYOVD) technique, leveraging a legitimate but vulnerable driver (ardrv.sys) associated with OPSWAT AppRemover to escalate privileges and disable security software. Attackers distribute compressed archives containing an Inno Setup executable via phishing emails, using lures such as government notices, public health materials, and real estate documents relevant to Cambodia. The installer triggers a DLL side-loading chain using a signed Tencent executable, which then deploys the vulnerable driver and the Spark RAT payload.The RAT, written in Go, allows for remote control of compromised devices. The attack chain includes anti-sandbox checks and attempts to disable security products like Microsoft Defender and Huorong Internet Security. While exhibiting similarities to past Silver Fox threat actor activities, such as DLL sideloading and persistence mechanisms, definitive attribution is not yet established due to differences in payloads and lack of shared infrastructure. The presence of Chinese-language elements in the Spark RAT configuration suggests potential development or deployment links to Chinese-speaking environments.Source: The Hacker News
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
