Socprime
Localized Phishing Campaign Targets Cambodian Organizations with Multi-Stage Malware
Article Content
A recent cyber campaign has been identified targeting organizations in Cambodia, utilizing localized phishing lures. The attack employs a complex multi-stage infection chain, starting with an Inno Setup installer that leads to the deployment of SparkRAT malware. Key techniques include DLL sideloading, shellcode extraction from PNG files, and the abuse of the Bring Your Own Vulnerable Driver (BYOVD) method to disable security software. The campaign leverages themes relevant to Cambodian users, such as government notices and public health announcements. Evidence suggests the campaign has been active since at least late June 2026. Organizations are advised to enhance endpoint protection and monitor for suspicious driver installations. Specific vulnerabilities, such as CVE-2026-36425, should be patched to mitigate risks associated with token manipulation. The current status of the campaign remains ongoing, with potential for further exploitation.
Key Points: • Targeted phishing campaign focuses on Cambodian organizations. • Utilizes multi-stage malware delivery and DLL sideloading techniques. • Organizations should patch CVE-2026-36425 and monitor for suspicious activity.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.