Find notable cyber news and cases, enriched with sources, timelines, and signals.

Spark RAT phishing campaign targeting Cambodia

Campaign
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

A Spark RAT campaign is targeting individuals and organizations in Cambodia, using phishing archives, DLL sideloading, and a BYOVD step to disable defenses and install remote access tooling. The activity broadened lure themes across government notices, public health materials, real estate, and promotional content, increasing the chance of successful initial access. The intrusion chain also adds persistence and security-product tampering, raising the risk of sustained compromise.

Related Happenings

Operation DragonReturn tax-phishing campaign targeting Indian taxpayers

Campaign
H score31 First: 06.07.2026 13:58 Last: 06.07.2026 13:58 Sources 1

About this happening: The Operation DragonReturn campaign is using spear-phishing and fake tax-filing lures to push remote access trojans into Indian taxpayer and finance environments, crea...

Latest development: 08.07.2026 03:00

Updated reporting on July 8, 2026 added Cyderes findings that Operation DragonReturn also uses fake websites impersonating the Indian Income Tax Department to deliver ZIP archives disguised as the common offline utility. The same chain deploys two implants, including a Gh0st RAT derivative that connects to kkxqbh[.]top on port 6666 and an AsyncRAT-family RAT that connects to ouewop[.]com on port 6351, while separate C2 channels, session-wide injection, and multiple initial access vectors improve persistence and resilience.

Timeline

  1. 27.08.2026 14:00 2 articles · 9h ago

    Spark RAT campaign targets Cambodia with phishing archives and vulnerable driver abuse

    Initial Disclosure

    Individuals and organizations in Cambodia were targeted by a campaign delivering the open-source Spark RAT through phishing emails, compressed archives, Inno Setup, signed Tencent DLL sideloading, and a BYOVD step that loaded the vulnerable OPSWAT AppRemover driver ardrv.sys to escalate privileges and disable security software such as Microsoft Defender and Huorong Internet Security. Malicious artifacts were discovered between late June and early August 2026, and the activity was assessed as an unattributed cluster with only low-confidence links to the broader Silver Fox ecosystem.

    Show sources