Spark RAT Campaign Targets Cambodia via BYOVD Abuse of Vulnerable OPSWAT AppRemover Driver (CVE-2026-36425)

Spark RAT Campaign Targets Cambodia via BYOVD Abuse of (TL-2026-2182) is a high-severity malware campaign scored CVSS 6.5, first published 2026-08-28. It has no confirmed attribution, affects OPSWAT AppRemover Driver (ardrv.sys), references 1 CVE (CVE-2026-36425), maps to 12 MITRE ATT&CK techniques (T1027, T1053, T1055), and is covered by 9 detection rules and 16 indicators of compromise.

Key facts for TL-2026-2182

Threat ID
TL-2026-2182
Severity
HIGH
CVSS
6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Status
ACTIVE
Category
MALWARE
First published
2026-08-28
Last reviewed
2026-08-28
Attribution confidence
LOW
Motivation
ESPIONAGE
Target sectors
government administration, health, realestate, generalpublic
Target regions
Southeast Asia, cambodia
Detection rules
9
Indicators of compromise
16

Malware and tooling in Spark RAT Campaign Targets Cambodia via BYOVD Abuse of

Malware and tooling: SparkRAT

An unattributed threat cluster targeted individuals and organizations in Cambodia between late June and early August 2026 with phishing emails delivering Inno Setup installers that side-load malware through a signed Tencent binary, decrypt PNG-embedded shellcode, and abuse a vulnerable OPSWAT AppRemover driver (ardrv.sys, CVE-2026-36425) via BYOVD to terminate Microsoft Defender, Huorong Internet Security, Tencent PC Manager and 360 Security before deploying the open-source Spark RAT.

How Spark RAT Campaign Targets Cambodia via BYOVD Abuse of works

Acronis's Threat Research Unit (TRU) identified malicious artifacts between late June and early August 2026 belonging to a multi-stage infection chain aimed at Cambodian individuals and organizations. Victims receive phishing emails carrying compressed archives with an Inno Setup installer disguised behind localized lures such as "Cambodian Government Notice on COVID-19 Prevention and Control (July 7).docx.exe", along with public-health, dental-record, real-estate and promotional-offer themes. Running the installer triggers a DLL side-loading chain in which the signed Tencent executable F7u00ex.exe loads the malicious DLL WfoY.qf. The loader performs timing-based anti-sandbox checks and process enumeration for installed security software, then decrypts shellcode embedded inside PNG payload containers (BssBfeFFoA3A.nz, d7zzQhzRglBv.es, cnV.rb, 56360VK1ES8.yvap) to run a second-stage payload.

The second stage checks for SYSTEM privileges by accessing winlogon.exe's token for impersonation. If elevated, it loads the legitimately signed but vulnerable OPSWAT AppRemover kernel driver ardrv.sys and abuses CVE-2026-36425 — an improper-access-control flaw in IOCTL handler 0x2420031 that lets any local caller submit unauthenticated process-termination requests via \\.\ardrv — in a Bring-Your-Own-Vulnerable-Driver (BYOVD) technique to kill Microsoft Defender, Huorong Internet Security, Tencent PC Manager and 360 Security processes, patch AMSI and ETW, and add Defender exclusions. The malware then injects shellcode into vssvc.exe, ctfmon.exe and svchost.exe and establishes persistence via a Windows service and scheduled task both named TaskHandler. If privileges are not elevated, the malware falls back directly to establishing the same service/scheduled-task persistence without the driver-abuse step.

The final payload is Spark RAT, an open-source, Go-based, cross-platform remote access trojan (github.com/XZB-1248/Spark) that communicates with its operators over WebSocket. Observed C2 infrastructure is sx.nuihuw.com:443 (primary) and nuihuw.top:443 (backup). Acronis assesses low-confidence tactical overlap with the Chinese-speaking Silver Fox syndicate — based on shared targeting of Huorong processes, DLL side-loading through signed applications, multi-stage delivery, and Defender-exclusion tradecraft — but found no shared infrastructure, certificates, or code reuse, and tracks the cluster as unattributed with possible Chinese-language development or deployment links.

MITRE ATT&CK techniques used in TL-2026-2182

Defense Evasion

T1027 Obfuscated Files or Information; T1055 Process Injection; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion; T1574 Hijack Execution Flow

Persistence

T1053 Scheduled Task/Job; T1543 Create or Modify System Process

Discovery

T1057 Process Discovery

Command and Control

T1071 Application Layer Protocol

defense-impairment

T1112 Modify Registry; T1685 Disable or Modify Tools

Initial Access

T1566 Phishing

Affected products and versions in Spark RAT Campaign Targets Cambodia via BYOVD Abuse of

  • OPSWAT — AppRemover Driver (ardrv.sys)
    Vulnerable versions: v2017.10.02.1551 and earlier
    Fixed in: newer than v2017.10.02.1551

Remediation for Spark RAT Campaign Targets Cambodia via BYOVD Abuse of

Patches

  • Update OPSWAT AppRemover Driver to a version newer than v2017.10.02.1551 (CVE-2026-36425)

Immediate actions

  • Add ardrv.sys (SHA256 07c5209bf83065fe760f4fee4ed2308b0c523671f68ca73a3854c2c8c28c0541 and variants) to Microsoft's vulnerable driver blocklist / WDAC-HVCI policy
  • Block outbound network connections to sx.nuihuw.com and nuihuw.top on port 443
  • Hunt for a service or scheduled task named TaskHandler created via sc create / schtasks /create
  • Alert on unsigned or anomalous DLLs (e.g. WfoY.qf) loaded by Tencent-signed executables (DLL side-loading)
  • Monitor for process injection into vssvc.exe, ctfmon.exe, and svchost.exe

Workarounds

  • Enforce Microsoft's vulnerable driver blocklist (HVCI) to prevent ardrv.sys from loading
  • Restrict device object access to \\.\ardrv to authorized/administrative accounts only

Longer-term hardening

  • Update or remove OPSWAT AppRemover (ardrv.sys) to a version newer than v2017.10.02.1551
  • Deploy EDR with kernel driver load monitoring and BYOVD-specific detection
  • Restrict local access to raw kernel device objects such as \\.\ardrv via ACL hardening
  • Deliver region-specific phishing awareness training referencing government/health/real-estate themed lures used against Cambodian targets

CVEs associated with Spark RAT Campaign Targets Cambodia via BYOVD Abuse of

CVE-2026-36425

Weaknesses (CWE) in Spark RAT Campaign Targets Cambodia via BYOVD Abuse of

CWE-269

Timeline of Spark RAT Campaign Targets Cambodia via BYOVD Abuse of

  • CVE request for the OPSWAT AppRemover ardrv.sys improper access control flaw submitted by researcher Jehad Abudagga
  • CVE-2026-36425 formally assigned
  • Acronis TRU observes the first malicious artifacts of the Cambodia-targeted campaign (late June 2026)
  • Phishing lure "Cambodian Government Notice on COVID-19 Prevention and Control (July 7).docx.exe" distributed, dated to this campaign wave
  • Public advisory and proof-of-concept for CVE-2026-36425 published on GitHub (redteamfortress/CVE-2026-36425)
  • Acronis TRU's observed campaign artifacts end (early August 2026)
  • The Hacker News publishes coverage summarizing the Acronis TRU findings
  • Acronis Threat Research Unit publishes "Cambodia-focused cluster uses multistage infection chain with localized lures"
  • SentinelOne includes the campaign in its "Good, the Bad and the Ugly in Cybersecurity – Week 35" roundup

Sources cited for Spark RAT Campaign Targets Cambodia via BYOVD Abuse of

More in malware

Detection coverage for TL-2026-2182

As of 2026-08-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2182 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats