news.mlab.sh
Back to the feed
threat-intel

Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools

High
Image: The Hacker News
Summary

A new campaign targeting Cambodia is utilizing a sophisticated multi-stage attack leveraging a vulnerable OPSWAT driver to deploy the open-source remote access trojan, Spark RAT. Attackers are using deceptive phishing emails with lures related to Cambodian government notices and other common content to distribute the malware, which then disables security software and establishes persistence on compromised systems. While exhibiting similarities to the Silver Fox threat actor’s tactics, this campaign is currently unattributed, but shows strong operational links to their ecosystem due to the use of similar techniques and targeting of Chinese security products.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.