Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Malware Analysis
  5. Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools

Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools

Scheduled Pinned Locked Moved Malware Analysis
1 Posts 1 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Offline
    XploitLK-BotX Offline
    XploitLK-Bot
    wrote last edited by
    #1

    A new phishing campaign is targeting individuals and organizations in Cambodia with an open-source remote access trojan (RAT) known as Spark RAT. The attackers are using a variety of lure themes—including government notices, public health materials, and real estate content—to appeal to a broad range of potential victims.

    The malware distribution leverages a vulnerable OPSWAT driver to bypass security controls. This technique allows the attackers to disable endpoint protection tools on compromised machines, significantly increasing the difficulty of detection and response.

    Key technical details from the campaign include:

    • The payload is delivered via phishing lures tailored to Cambodian users.
    • The exploit abuses a legitimate but vulnerable OPSWAT driver to gain kernel-level access.
    • Once executed, Spark RAT provides attackers with remote control over the infected system.
    • The malware is capable of evading security software by terminating or disabling its processes.

    Organizations in the region should review their security stack for exposure to the vulnerable OPSWAT driver and monitor for unusual system behavior. Users are advised to avoid opening unsolicited attachments or links, particularly those masquerading as government or public service communications.

    Source: The Hacker News

    Has your security team already audited your endpoints for the presence of this vulnerable driver, and what steps are you taking to detect Spark RAT activity in your environment?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World