Cyber Campaign Targets Cambodia with Spark RAT via BYOVD Technique

Cyber Campaign Targets Cambodia with Spark RAT via BYOVD Technique

First seen 28 Aug 2026, 21:54 UTC ThehackernewsScworld 69.0

Article Content

Browse articles
ThreatCluster

A new cyber campaign has emerged, targeting individuals and organizations in Cambodia with the Spark RAT, an open-source remote access trojan. The attackers utilize a sophisticated multi-stage infection chain, employing a 'bring your own vulnerable driver' (BYOVD) technique that exploits a legitimate driver (ardrv.sys) linked to OPSWAT AppRemover to escalate privileges and disable security software. Victims are lured through phishing emails containing compressed archives with an Inno Setup executable, disguised as government notices, public health materials, and real estate documents. The attack chain incorporates anti-sandbox checks and attempts to disable security products like Microsoft Defender. While the campaign shows similarities to previous activities by the Silver Fox threat actor, definitive attribution remains unclear due to differences in payloads. The Spark RAT, written in Go, allows attackers to remotely control compromised devices. The presence of Chinese-language elements in the configuration hints at possible links to Chinese-speaking environments.

Key Points: • Spark RAT targets Cambodia using sophisticated phishing techniques. • Attackers exploit a vulnerable driver to escalate privileges and disable security tools. • The campaign shows similarities to past Silver Fox activities but lacks definitive attribution.

Timeline

2026-08-27
Cyber campaign targeting Cambodia reported
The Hacker News reported on a new campaign distributing Spark RAT in Cambodia, utilizing phishing emails and BYOVD techniques.
Thehackernews
2026-08-28
Detailed report on Spark RAT campaign released
Scworld published a brief detailing the multi-stage infection chain and the use of localized lures to target Cambodian victims.
Scworld