Spark RAT Campaign Targets Cambodia via BYOVD Abuse of Vulnerable OPSWAT AppRemover Driver (CVE-2026-36425) — Threadlinqs Intelligence
As of 2026-08-28, Spark RAT Campaign Targets Cambodia via BYOVD Abuse of Vulnerable OPSWAT AppRemover Driver (CVE-2026-36425) is a high-severity malware threat attributed to Unknown (unattributed cluster (Unknown (possible Chinese-language development/deployment links, low confidence)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 16 indicators of compromise.
Threat ID: TL-2026-2182 · Severity: HIGH · CVSS: 6.5 · Status: ACTIVE · Category: MALWARE
Attribution: Unknown (unattributed cluster · Unknown (possible Chinese-language development/deployment links, low confidence) · ESPIONAGE
An unattributed threat cluster targeted individuals and organizations in Cambodia between late June and early August 2026 with phishing emails delivering Inno Setup installers that side-load malware
Acronis's Threat Research Unit (TRU) identified malicious artifacts between late June and early August 2026 belonging to a multi-stage infection chain aimed at Cambodian individuals and organizations. Victims receive phishing emails carrying compressed archives with an Inno Setup installer disguised behind localized lures such as "Cambodian Government Notice on COVID-19 Prevention and Control (July 7).docx.exe", along with public-health, dental-record, real-estate and promotional-offer themes. Running the installer triggers a DLL side-loading chain in which the signed Tencent executable F7u00ex.exe loads the malicious DLL WfoY.qf. The loader performs timing-based anti-sandbox checks and process enumeration for installed security software, then decrypts shellcode embedded inside PNG payload containers (BssBfeFFoA3A.nz, d7zzQhzRglBv.es, cnV.rb, 56360VK1ES8.yvap) to run a second-stage payload.
The second stage checks for SYSTEM privileges by accessing winlogon.exe's token for impersonation. If elevated, it loads the legitimately signed but vulnerable OPSWAT AppRemover kernel driver ardrv.sys and abuses CVE-2026-36425 — an improper-access-control flaw in IOCTL handler 0x2420031 that lets any local caller submit unauthenticated process-termination requests via \\.\ardrv — in a Bring-Your-Own-Vulnerable-Driver (BYOVD) technique to kill Microsoft Defender, Huorong Internet Security, Tencent PC Manager and 360 Security processes, patch AMSI and ETW, and add Defender exclusions. The malware then injects shellcode into vssvc.exe, ctfmon.exe and svchost.exe and establishes persistence via a Windows service and scheduled task both named TaskHandler. If privileges are not elevated, the malware falls back directly to establishing the same service/scheduled-task persistence without the driver-abuse step.
The final payload is Spark RAT, an open-source, Go-based, cross-platform remote access trojan (github.com/XZB-1248/Spark) that communicates with its operators over WebSocket. Observed C2 infrastructure is sx.nuihuw.com:443 (primary) and nuihuw.top:443 (backup). Acronis assesses low-confidence tactical overlap with the Chinese-speaking Silver Fox syndicate — based on shared targeting of Huorong processes, DLL side-loading through signed applications, multi-stage delivery, and Defender-exclusion tradecraft — but found no shared infrastructure, certificates, or code reuse, and tracks the cluster as unattributed with possible Chinese-language development or deployment links.
Target sectors: government administration, health, realestate, generalpublic
Target regions: Southeast Asia, cambodia
Timeline
- CVE request for the OPSWAT AppRemover ardrv.sys improper access control flaw submitted by researcher Jehad Abudagga
- CVE-2026-36425 formally assigned
- Acronis TRU observes the first malicious artifacts of the Cambodia-targeted campaign (late June 2026)
- Phishing lure "Cambodian Government Notice on COVID-19 Prevention and Control (July 7).docx.exe" distributed, dated to this campaign wave
- Public advisory and proof-of-concept for CVE-2026-36425 published on GitHub (redteamfortress/CVE-2026-36425)
- Acronis TRU's observed campaign artifacts end (early August 2026)
- Acronis Threat Research Unit publishes "Cambodia-focused cluster uses multistage infection chain with localized lures"
- The Hacker News publishes coverage summarizing the Acronis TRU findings
- SentinelOne includes the campaign in its "Good, the Bad and the Ugly in Cybersecurity – Week 35" roundup
Detections & IOCs
As of 2026-09-04, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 16 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, CVE-2026-36425, T1566, T1574, T1027, T1140, T1055, T1685, T1112, T1543, T1053, T1497