Spark RAT phishing campaign targeting Cambodia
Campaign
Summary
Hide ▲
Show ▼
A Spark RAT campaign is targeting individuals and organizations in Cambodia, using phishing archives, DLL sideloading, and a BYOVD step to disable defenses and install remote access tooling. The activity broadened lure themes across government notices, public health materials, real estate, and promotional content, increasing the chance of successful initial access. The intrusion chain also adds persistence and security-product tampering, raising the risk of sustained compromise.
Related Happenings
Operation DragonReturn tax-phishing campaign targeting Indian taxpayers
Campaign
H score31
First: 06.07.2026 13:58
Last: 06.07.2026 13:58
Sources 1
About this happening:
The Operation DragonReturn campaign is using spear-phishing and fake tax-filing lures to push remote access trojans into Indian taxpayer and finance environments, crea...
Operation DragonReturn tax-phishing campaign targeting Indian taxpayers
CampaignAbout this happening: The Operation DragonReturn campaign is using spear-phishing and fake tax-filing lures to push remote access trojans into Indian taxpayer and finance environments, crea...
Latest development: 08.07.2026 03:00
Updated reporting on July 8, 2026 added Cyderes findings that Operation DragonReturn also uses fake websites impersonating the Indian Income Tax Department to deliver ZIP archives disguised as the common offline utility. The same chain deploys two implants, including a Gh0st RAT derivative that connects to kkxqbh[.]top on port 6666 and an AsyncRAT-family RAT that connects to ouewop[.]com on port 6351, while separate C2 channels, session-wide injection, and multiple initial access vectors improve persistence and resilience.
Timeline
-
27.08.2026 14:00 2 articles · 9h ago
Spark RAT campaign targets Cambodia with phishing archives and vulnerable driver abuse
Initial DisclosureIndividuals and organizations in Cambodia were targeted by a campaign delivering the open-source Spark RAT through phishing emails, compressed archives, Inno Setup, signed Tencent DLL sideloading, and a BYOVD step that loaded the vulnerable OPSWAT AppRemover driver ardrv.sys to escalate privileges and disable security software such as Microsoft Defender and Huorong Internet Security. Malicious artifacts were discovered between late June and early August 2026, and the activity was assessed as an unattributed cluster with only low-confidence links to the broader Silver Fox ecosystem.
Show sources
- Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools — thehackernews.com — 27.08.2026 14:00
- Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools — thehackernews.com — 27.08.2026 14:00