Spark RAT Campaign Targets Cambodia via BYOVD Abuse of Vulnerable OPSWAT AppRemover Driver (CVE-2026-36425)
Spark RAT Campaign Targets Cambodia via BYOVD Abuse of (TL-2026-2182) is a high-severity malware campaign scored CVSS 6.5, first published 2026-08-28. It has no confirmed attribution, affects OPSWAT AppRemover Driver (ardrv.sys), references 1 CVE (CVE-2026-36425), maps to 12 MITRE ATT&CK techniques (T1027, T1053, T1055), and is covered by 9 detection rules and 16 indicators of compromise.
Key facts for TL-2026-2182
- Threat ID
- TL-2026-2182
- Severity
- HIGH
- CVSS
- 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-08-28
- Last reviewed
- 2026-08-28
- Attribution confidence
- LOW
- Motivation
- ESPIONAGE
- Target sectors
- government administration, health, realestate, generalpublic
- Target regions
- Southeast Asia, cambodia
- Detection rules
- 9
- Indicators of compromise
- 16
Malware and tooling in Spark RAT Campaign Targets Cambodia via BYOVD Abuse of
Malware and tooling: SparkRAT
An unattributed threat cluster targeted individuals and organizations in Cambodia between late June and early August 2026 with phishing emails delivering Inno Setup installers that side-load malware through a signed Tencent binary, decrypt PNG-embedded shellcode, and abuse a vulnerable OPSWAT AppRemover driver (ardrv.sys, CVE-2026-36425) via BYOVD to terminate Microsoft Defender, Huorong Internet Security, Tencent PC Manager and 360 Security before deploying the open-source Spark RAT.
How Spark RAT Campaign Targets Cambodia via BYOVD Abuse of works
Acronis's Threat Research Unit (TRU) identified malicious artifacts between late June and early August 2026 belonging to a multi-stage infection chain aimed at Cambodian individuals and organizations. Victims receive phishing emails carrying compressed archives with an Inno Setup installer disguised behind localized lures such as "Cambodian Government Notice on COVID-19 Prevention and Control (July 7).docx.exe", along with public-health, dental-record, real-estate and promotional-offer themes. Running the installer triggers a DLL side-loading chain in which the signed Tencent executable F7u00ex.exe loads the malicious DLL WfoY.qf. The loader performs timing-based anti-sandbox checks and process enumeration for installed security software, then decrypts shellcode embedded inside PNG payload containers (BssBfeFFoA3A.nz, d7zzQhzRglBv.es, cnV.rb, 56360VK1ES8.yvap) to run a second-stage payload.
The second stage checks for SYSTEM privileges by accessing winlogon.exe's token for impersonation. If elevated, it loads the legitimately signed but vulnerable OPSWAT AppRemover kernel driver ardrv.sys and abuses CVE-2026-36425 — an improper-access-control flaw in IOCTL handler 0x2420031 that lets any local caller submit unauthenticated process-termination requests via \\.\ardrv — in a Bring-Your-Own-Vulnerable-Driver (BYOVD) technique to kill Microsoft Defender, Huorong Internet Security, Tencent PC Manager and 360 Security processes, patch AMSI and ETW, and add Defender exclusions. The malware then injects shellcode into vssvc.exe, ctfmon.exe and svchost.exe and establishes persistence via a Windows service and scheduled task both named TaskHandler. If privileges are not elevated, the malware falls back directly to establishing the same service/scheduled-task persistence without the driver-abuse step.
The final payload is Spark RAT, an open-source, Go-based, cross-platform remote access trojan (github.com/XZB-1248/Spark) that communicates with its operators over WebSocket. Observed C2 infrastructure is sx.nuihuw.com:443 (primary) and nuihuw.top:443 (backup). Acronis assesses low-confidence tactical overlap with the Chinese-speaking Silver Fox syndicate — based on shared targeting of Huorong processes, DLL side-loading through signed applications, multi-stage delivery, and Defender-exclusion tradecraft — but found no shared infrastructure, certificates, or code reuse, and tracks the cluster as unattributed with possible Chinese-language development or deployment links.
MITRE ATT&CK techniques used in TL-2026-2182
Defense Evasion
T1027 Obfuscated Files or Information; T1055 Process Injection; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion; T1574 Hijack Execution Flow
Persistence
T1053 Scheduled Task/Job; T1543 Create or Modify System Process
Discovery
Command and Control
T1071 Application Layer Protocol
defense-impairment
T1112 Modify Registry; T1685 Disable or Modify Tools
Initial Access
Affected products and versions in Spark RAT Campaign Targets Cambodia via BYOVD Abuse of
- OPSWAT — AppRemover Driver (ardrv.sys)
Vulnerable versions: v2017.10.02.1551 and earlier
Fixed in: newer than v2017.10.02.1551
Remediation for Spark RAT Campaign Targets Cambodia via BYOVD Abuse of
Patches
- Update OPSWAT AppRemover Driver to a version newer than v2017.10.02.1551 (CVE-2026-36425)
Immediate actions
- Add ardrv.sys (SHA256 07c5209bf83065fe760f4fee4ed2308b0c523671f68ca73a3854c2c8c28c0541 and variants) to Microsoft's vulnerable driver blocklist / WDAC-HVCI policy
- Block outbound network connections to sx.nuihuw.com and nuihuw.top on port 443
- Hunt for a service or scheduled task named TaskHandler created via sc create / schtasks /create
- Alert on unsigned or anomalous DLLs (e.g. WfoY.qf) loaded by Tencent-signed executables (DLL side-loading)
- Monitor for process injection into vssvc.exe, ctfmon.exe, and svchost.exe
Workarounds
- Enforce Microsoft's vulnerable driver blocklist (HVCI) to prevent ardrv.sys from loading
- Restrict device object access to \\.\ardrv to authorized/administrative accounts only
Longer-term hardening
- Update or remove OPSWAT AppRemover (ardrv.sys) to a version newer than v2017.10.02.1551
- Deploy EDR with kernel driver load monitoring and BYOVD-specific detection
- Restrict local access to raw kernel device objects such as \\.\ardrv via ACL hardening
- Deliver region-specific phishing awareness training referencing government/health/real-estate themed lures used against Cambodian targets
CVEs associated with Spark RAT Campaign Targets Cambodia via BYOVD Abuse of
CVE-2026-36425
Weaknesses (CWE) in Spark RAT Campaign Targets Cambodia via BYOVD Abuse of
CWE-269
Timeline of Spark RAT Campaign Targets Cambodia via BYOVD Abuse of
- CVE request for the OPSWAT AppRemover ardrv.sys improper access control flaw submitted by researcher Jehad Abudagga
- CVE-2026-36425 formally assigned
- Acronis TRU observes the first malicious artifacts of the Cambodia-targeted campaign (late June 2026)
- Phishing lure "Cambodian Government Notice on COVID-19 Prevention and Control (July 7).docx.exe" distributed, dated to this campaign wave
- Public advisory and proof-of-concept for CVE-2026-36425 published on GitHub (redteamfortress/CVE-2026-36425)
- Acronis TRU's observed campaign artifacts end (early August 2026)
- The Hacker News publishes coverage summarizing the Acronis TRU findings
- Acronis Threat Research Unit publishes "Cambodia-focused cluster uses multistage infection chain with localized lures"
- SentinelOne includes the campaign in its "Good, the Bad and the Ugly in Cybersecurity – Week 35" roundup
Sources cited for Spark RAT Campaign Targets Cambodia via BYOVD Abuse of
- Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools
- The Good, the Bad and the Ugly in Cybersecurity – Week 35
- Cambodia-focused cluster uses multistage infection chain with localized lures
- Cambodia-focused cluster uses multistage infection chain with localized lures (mirror)
- CVE-2026-36425 OPSWAT AppRemover (ardrv.sys) improper access control advisory
- NVD - CVE-2026-36425
- OPSWAT AppRemover Driver (ardrv.sys) - LOLDrivers
- Introducing CVE-2026-36425 | OPSWAT EDR Terminator
- XZB-1248/Spark - open-source cross-platform RAT (GitHub)
- OPSWAT OESIS Framework - Application Removal
More in malware
- Trusted AI Platforms Weaponized as Malware Distribution Channels: Claude Artifacts, ChatGPT, and Grok Abused Across SectopRAT, MacSync, and AMOS Campaigns
- Rapuncel Infostealer Uses Microsoft-Signed Driver to Kill 145 Security Tools via Fake LastPass Authenticator GitHub Repos
- EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentials
- Jade Sleet (North Korea) Compromises Indian IT Provider via FLATROOF and ROOFDECK macOS Backdoors
- PowerShell Cryptomining Loader Abuses Registry-Resident Scripts, DNS TXT Records, and PNG/WAV Steganography for Stealth C2
Detection coverage for TL-2026-2182
As of 2026-08-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2182 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.