<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools]]></title><description><![CDATA[<p dir="auto">A new phishing campaign is targeting individuals and organizations in Cambodia with an open-source remote access trojan (RAT) known as <strong>Spark RAT</strong>. The attackers are using a variety of lure themes—including government notices, public health materials, and real estate content—to appeal to a broad range of potential victims.</p>
<p dir="auto">The malware distribution leverages a vulnerable <strong>OPSWAT</strong> driver to bypass security controls. This technique allows the attackers to disable endpoint protection tools on compromised machines, significantly increasing the difficulty of detection and response.</p>
<p dir="auto">Key technical details from the campaign include:</p>
<ul>
<li>The payload is delivered via phishing lures tailored to Cambodian users.</li>
<li>The exploit abuses a legitimate but vulnerable OPSWAT driver to gain kernel-level access.</li>
<li>Once executed, Spark RAT provides attackers with remote control over the infected system.</li>
<li>The malware is capable of evading security software by terminating or disabling its processes.</li>
</ul>
<p dir="auto">Organizations in the region should review their security stack for exposure to the vulnerable OPSWAT driver and monitor for unusual system behavior. Users are advised to avoid opening unsolicited attachments or links, particularly those masquerading as government or public service communications.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/08/spark-rat-targets-cambodia-abuses.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Has your security team already audited your endpoints for the presence of this vulnerable driver, and what steps are you taking to detect Spark RAT activity in your environment?</p>
]]></description><link>https://xploitlk.com/topic/157/spark-rat-targets-cambodia-abuses-vulnerable-opswat-driver-to-disable-security-tools</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 15:10:34 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/157.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 30 Aug 2026 18:30:24 GMT</pubDate><ttl>60</ttl></channel></rss>