Executive Summary
Between June and August 2026, threat actors conducted a sophisticated campaign targeting individuals and organizations in Cambodia using Spark RAT, an open-source remote access trojan. The multi-stage attack leveraged phishing emails with localized lures including government notices and health materials to distribute Inno Setup executables. The campaign employed advanced techniques including DLL sideloading, bring-your-own-vulnerable-driver (BYOVD) tactics using OPSWAT's ardrv.sys driver, and multi-layered persistence mechanisms to disable security software and maintain access to compromised systems.
This incident highlights the growing sophistication of nation-state and advanced persistent threat actors who are increasingly leveraging legitimate-but-vulnerable drivers to bypass modern endpoint security solutions, representing a critical evolution in attack methodologies that organizations must address immediately.
Why This Matters Now
The abuse of legitimate signed drivers to disable security tools represents a critical blind spot in current defense strategies, as traditional security solutions struggle to detect and prevent BYOVD attacks that exploit the trust model of digitally signed components.
Attack Path Analysis
Attackers targeting Cambodia used phishing emails with localized lures to deliver Spark RAT through multi-stage infection chains. The attack leveraged DLL sideloading, vulnerable OPSWAT drivers (CVE-2026-36425) for privilege escalation, and sophisticated anti-sandbox techniques to disable security tools and establish persistent remote access.
Kill Chain Progression
Initial Compromise
Description
Phishing emails with Cambodian government notices, health materials, and real estate lures delivered compressed archives containing Inno Setup executables to trick recipients into execution
Related CVEs
CVE-2026-36425
CVSS 6.5A privilege escalation vulnerability in OPSWAT AppRemover driver (ardrv.sys) allows attackers to gain SYSTEM privileges and disable security software.
Affected Products:
OPSWAT AppRemover Driver – ardrv.sys - vulnerable version
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Spearphishing Attachment
DLL Side-Loading
Exploitation for Privilege Escalation
Disable or Modify Tools
Dynamic-link Library Injection
Scheduled Task
Match Legitimate Name or Location
Process Hollowing
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software engineering techniques for secure development
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Access Privileges
Control ID: 500.02(g)
DORA – ICT risk management framework
Control ID: Article 8
CISA ZTMM 2.0 – Device Identity and Integrity
Control ID: Device Security
NIS2 Directive – Cybersecurity measures
Control ID: Article 21
ISO 27001:2022 – Management of technical vulnerabilities
Control ID: 8.8
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Spark RAT campaign specifically targets Cambodian government entities using official notices as lures, enabling privileged access escalation and security software bypass.
Health Care / Life Sciences
Public health materials and dental examination records used as infection vectors expose healthcare systems to RAT deployment and HIPAA compliance violations.
Real Estate/Mortgage
Real estate documents serve as primary attack lures, threatening property transaction systems with remote access trojans and financial data exfiltration risks.
Computer/Network Security
BYOVD technique exploiting vulnerable OPSWAT drivers directly compromises security infrastructure, disabling endpoint protection and bypassing AMSI/ETW detection mechanisms.
Sources
- Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Toolshttps://thehackernews.com/2026/08/spark-rat-targets-cambodia-abuses.htmlVerified
- Cambodia-Focused Cluster Uses Multi-Stage Infection Chain With Localized Lureshttps://www.acronis.com/en/tru/posts/cambodia-focused-cluster-uses-multi-stage-infection-chain-with-localized-lures/Verified
- Spark RAT GitHub Repositoryhttps://github.com/XZB-1248/SparkVerified
- NVD CVE-2026-36425 Detailshttps://nvd.nist.gov/vuln/detail/CVE-2026-36425Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF would have significantly constrained this Spark RAT campaign by limiting lateral movement pathways and reducing blast radius through workload segmentation. The attack's multi-stage progression across compromised Cambodian systems would likely have been contained to isolated network segments.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial workload compromise would likely still occur, but segmentation policies would immediately constrain the attacker's ability to reach additional cloud resources and limit reconnaissance of the broader infrastructure environment.
Control: Zero Trust Segmentation
Mitigation: While local privilege escalation might still succeed on the compromised host, zero trust policies would likely restrict the elevated account's network reachability and prevent access to sensitive workloads or administrative interfaces across segmented environments.
Control: East-West Traffic Security
Mitigation: Cross-workload communication attempts would likely be blocked by east-west traffic inspection, significantly limiting the attacker's ability to pivot between hosts and constraining the infection to isolated network segments rather than enterprise-wide propagation.
Control: Multicloud Visibility & Control
Mitigation: Command and control traffic patterns would likely be detected through behavioral analysis, and communication pathways could be dynamically restricted to limit the attacker's operational control and reduce the effectiveness of remote access capabilities.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts would likely be constrained by egress policies that restrict outbound data flows from compromised workloads, limiting the volume and types of information that could be successfully transmitted to attacker-controlled infrastructure.
Despite successful initial compromise, the overall impact scope would likely be significantly reduced due to workload isolation, with attackers constrained to limited network segments rather than achieving broad organizational access across cloud infrastructure.
Impact at a Glance
Affected Business Functions
- Government Administrative Services
- Public Health Records Management
- Real Estate Documentation Systems
- Information Security Operations
Estimated downtime: 5 days
Estimated loss: $75,000
Government documents, public health records, real estate documentation, and potentially sensitive administrative data from Cambodian organizations and individuals targeted through localized phishing campaigns
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to prevent lateral movement between workloads and limit blast radius of compromised endpoints
- • Deploy Egress Security & Policy Enforcement to block unauthorized outbound communications from RAT payloads to external C2 infrastructure
- • Enable Multicloud Visibility & Control to detect anomalous process injection activities and suspicious automation patterns
- • Utilize Threat Detection & Anomaly Response capabilities to identify remote access tool deployment and baseline deviations
- • Enforce Inline IPS (Suricata) inspection to detect and block known exploit patterns and malicious payload delivery attempts



