Localized Phishing Campaign Targets Cambodian Organizations with Multi-Stage Malware

Localized Phishing Campaign Targets Cambodian Organizations with Multi-Stage Malware

First seen 28 Aug 2026, 15:22 UTC AcronisSocprime 73.5

Article Content

Browse articles
ThreatCluster

A recent cyber campaign has been identified targeting organizations in Cambodia, utilizing localized phishing lures. The attack employs a complex multi-stage infection chain, starting with an Inno Setup installer that leads to the deployment of SparkRAT malware. Key techniques include DLL sideloading, shellcode extraction from PNG files, and the abuse of the Bring Your Own Vulnerable Driver (BYOVD) method to disable security software. The campaign leverages themes relevant to Cambodian users, such as government notices and public health announcements. Evidence suggests the campaign has been active since at least late June 2026. Organizations are advised to enhance endpoint protection and monitor for suspicious driver installations. Specific vulnerabilities, such as CVE-2026-36425, should be patched to mitigate risks associated with token manipulation. The current status of the campaign remains ongoing, with potential for further exploitation.

Key Points: • Targeted phishing campaign focuses on Cambodian organizations. • Utilizes multi-stage malware delivery and DLL sideloading techniques. • Organizations should patch CVE-2026-36425 and monitor for suspicious activity.

Timeline

2026-06-18
First public PoC for CVE-2026-36425
Proof-of-concept code for the vulnerability was released, highlighting its exploit potential.
Acronis
2026-07-16
CVE-2026-36425 published
CVE-2026-36425 was officially published, detailing a critical vulnerability in a widely used driver.
Socprime
2026-08-26
Acronis report published
Acronis' Threat Research Unit released a detailed analysis of the Cambodia-focused cyber campaign.
Acronis
2026-08-28
Socprime report published
Socprime published findings on the same Cambodia-focused threat cluster, confirming ongoing activity.
Socprime
Recent
Ongoing campaign identified
A cyber campaign targeting Cambodian organizations has been confirmed, utilizing localized lures and multi-stage malware.
Acronis