
People and organizations in Cambodia have emerged because the goal of a brand new marketing campaign that delivers an open-source distant entry trojan (RAT) referred to as Spark RAT.
“The samples make use of various lure themes, suggesting an effort to attraction to a broad vary of potential victims. These embody authorities notices, public well being supplies, actual estate-related content material, and different matters,” Acronis Risk Analysis Unit (TRU) researchers Darrel Virtusio and Subhajeet Singha stated in an evaluation printed Wednesday.
The multi-stage assault is notable for using the carry your personal susceptible driver (BYOVD) method to load a legitimate-but-vulnerable driver related to OPSWAT AppRemover (“ardrv.sys”) to escalate privileges and neutralize safety software program.
Assault chains probably make use of concentrating on phishing emails to distribute compressed archives containing an Inno Setup executable and trick recipients into operating it utilizing wide-ranging lures, together with Cambodian authorities notices, public well being bulletins, dental examination data, actual property paperwork, and promotional affords.
Acronis stated it found quite a lot of malicious artifacts between late June by way of early August 2026, though it is unclear if the marketing campaign stays ongoing.
The Inno Setup installer is designed to set off a DLL side-loading chain utilizing a signed Tencent executable, which then delivers interim payloads liable for deploying the susceptible “ardrv.sys” after which launching the Spark RAT payload. Spark RAT is an open-source, Go-based cross-platform RAT that allows distant management of compromised units.
The DLL loader additionally carries out a timing-based anti-sandbox test to detect environments that shorten or manipulate sleep delays, and proceeds to terminate execution if the elapsed time falls exterior the anticipated vary. Moreover, it critiques operating processes for these associated to Huorong Web Safety (“HipsTray.exe”), a Chinese language endpoint safety program.
If the method is current, the loader makes an attempt to weaken the privileges of the safety product. Within the subsequent stage, it decrypts shellcode hid inside a PNG file current within the archive to run a second stager, which verifies whether it is operating with SYSTEM privileges.
“Based mostly on these checks, the payload selects one among two execution modes,” Acronis stated. “Whether it is already operating as SYSTEM, it proceeds on to inject mode, bypassing the persistence setup and executing the following stage. In any other case, it enters setup mode, the place it establishes persistence first, then executes the following stage.”
The inject mode works by parsing and decrypting shellcode embedded in one other PNG file from the archive, after which injecting it into “vssvc.exe” and executing it throughout the context of the goal course of. To make sure the injected payload stays operating, it displays the “vssvc.exe” occasion and re-injects the shellcode if the method terminates or restarts with a brand new PID.
Within the setup mode, the malware reads and decrypts the shellcode from the identical file, after which it checks for a listing of hard-coded processes related to Qihoo 360. If none of them are discovered, it units up a Home windows service-based persistence mechanism to launch the binary that sideloads the DLL to relaunch your entire cycle once more. After establishing persistence on the host, it injects the shellcode into “vssvc.exe” like earlier than.
The payload performs the next sequence of actions –
- Try to patch AMSI and ETW associated performance
- Setup persistence utilizing a scheduled job
- Set up the ardrv.sys driver that is susceptible to CVE-2026-36425 to terminate security-related processes equivalent to Microsoft Defender, Huorong Web Safety, and Tencent PC Supervisor
- Learn and decrypt one other embedded payload from a 3rd PNG file to carry out user-mode termination of hard-coded safety processes
Concurrently, a fourth PNG-based payload file is processed to extract and decrypt shellcode that is injected into “ctfmon.exe,” finally resulting in the execution of Spark RAT.
Curiously, the BYOVD routine references quite a lot of different drivers, together with these a part of TrueSight and Zemana Anti-Malware SDK, each of which have been put to make use of by the Silver Fox risk actor previous to dropping Winos 4.0 (aka ValleyRAT). As well as, the concentrating on of Huorong safety processes has been repeatedly noticed in previous Silver Fox-related assaults.
Different Silver Fox-style indicators embody concentrating on overlaps, using DLL sideloading by way of a signed software, multi-stage payload supply, persistence by way of Home windows providers and scheduled duties, and Microsoft Defender exclusions. Regardless of these similarities, there’s not sufficient proof to definitively attribute the most recent exercise to the risk actor.
This evaluation, Acronis stated, is predicated on the absence of shared infrastructure, function-level code reuse, and matching certificates. One other essential differentiator is the selection of the malware itself. Whereas Silver Fox campaigns are recognized to leverage ValleyRAT and different customized payloads, it has not been attributed to the deployment of an open-source RAT.
“This distinction doesn’t rule out a relationship, since operators can change payloads, but it surely removes one of many stronger hyperlinks utilized in earlier attributions,” the cybersecurity firm added. “The Spark RAT configuration accommodates a Chinese language-language worth, and the malware targets a number of safety merchandise generally utilized in Chinese language-speaking environments.”
“We due to this fact observe the exercise as an unattributed cluster with doable Chinese language-language growth or deployment hyperlinks and operational similarities to the broader Silver Fox ecosystem. This evaluation stays low confidence and will change if further code, infrastructure, victimology, or different attributional proof is recognized.”

