Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools
A new campaign targeting Cambodia is utilizing a sophisticated multi-stage attack leveraging a vulnerable OPSWAT driver to deploy the open-source remote access trojan, Spark RAT. Attackers are using deceptive phishing emails with lures related to Cambodian government notices and other common content to distribute the malware, which then disables security software and establishes persistence on compromised systems. While exhibiting similarities to the Silver Fox threat actor’s tactics, this campaign is currently unattributed, but shows strong operational links to their ecosystem due to the use of similar techniques and targeting of Chinese security products.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
