Back Socprime Cambodia-Focused Threat Cluster Uses Localized Phishing and Multi
An unattributed threat cluster is targeting organizations in Cambodia with localized phishing lures. The attack relies on a complex multi-stage infection chain involving DLL sideloading, shellcode extraction from PNG files, and process injection. The campaign also abuses a Bring Your Own Vulnerable Driver (BYOVD) technique to disable security software.
The Acronis Threat Research Unit identified the campaign while analyzing compressed archives containing Cambodia-themed lures. Researchers traced the infection from an Inno Setup installer to the deployment of SparkRAT. The malware was also observed performing token manipulation, AMSI/ETW patching, and abusing the vulnerable arsdrv.sys driver to terminate security processes.
Organizations should deploy robust endpoint protection and monitor for suspicious driver installations, with particular attention to BYOVD activity. Patching vulnerabilities such as CVE-2026-36425 and limiting administrative privileges can reduce the impact of token manipulation. Monitoring unauthorized service creation and scheduled task activity can also help identify persistence.
If malicious activity is detected, affected hosts should be isolated immediately to prevent further lateral movement or C2 communication. Investigators should examine the C:\Drivers directory and inspect processes such as vssvc.exe , ctfmon.exe , and svchost.exe for injected code. Windows Event Logs should also be reviewed for suspicious sc.exe service creation and schtasks.exe modifications.
Prerequisite: The Telemetry & Baseline Pre-flight Check must have passed.
Rationale: This section details the precise execution of the adversary technique (TTP) designed to trigger the detection rule. The commands and narrative MUST directly reflect the TTPs identified and aim to generate the exact telemetry expected by the detection logic. Abstract or unrelated examples will lead to misdiagnosis.
Attack Narrative & Commands: An adversary has successfully established a foothold on a Windows workstation via a localized lure. Having performed credential dumping (T1055) to escalate privileges, the malware now attempts to establish an encrypted Command and Control (C2) channel. To avoid detection, the malware targets the specific infrastructure identified in the Cambodia-focused campaign: nuihuw.top . The simulation will use a PowerShell command to initiate a connection to this domain on port 443, mimicking the malware’s callback.
Regression Test Script:
Join SOC Prime's Detection as Code platform to improve visibility into threats most relevant to your business. To help you get started and drive immediate value, book a meeting now with SOC Prime experts.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
