By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Spark RAT Targets Cambodia, Abuses OPSWAT Driver to Disable Security

Individuals and organizations in Cambodia have become the primary targets of a recently identified cyber campaign distributing an open-source remote access trojan (RAT) known as Spark RAT. Threat intelligence from Acronis indicates that the attackers are employing a variety of lure themes to attract a broad spectrum of potential victims. These themes include official government notices, public health advisories, real estate advertisements, and other content designed to appear relevant and trustworthy to different user groups. The objective behind this diverse approach is to maximize the chances of successful initial infection across various sectors within Cambodia.
Upon successful infiltration, Spark RAT demonstrates a sophisticated capability to evade detection and disable security measures. A key tactic observed in the campaign involves the exploitation of a legitimate, but vulnerable, driver developed by OPSWAT, a technology company specializing in cybersecurity solutions. Specifically, the attackers are leveraging a signed driver that is part of the OPSWAT MetaAccess SDK. This driver, when compromised, allows the Spark RAT to gain elevated privileges on the infected system. These elevated privileges are then used to manipulate or disable critical security software, such as antivirus programs and endpoint detection and response (EDR) solutions, thereby creating a more permissive environment for the RAT to operate undetected.
The use of an open-source RAT like Spark suggests that the threat actors may have access to readily available tools, potentially lowering the barrier to entry for such attacks. Open-source malware can be modified and customized, making it harder to track and attribute. The campaign's focus on Cambodia, as reported by Acronis, highlights a specific regional targeting strategy. The exact motivations behind this targeted campaign remain under investigation, but typical objectives for RAT deployment include espionage, data theft, financial fraud, or preparing systems for further malicious activities like ransomware deployment.
Acronis's analysis underscores the evolving tactics of cybercriminals, who are increasingly adept at exploiting legitimate software components and drivers to bypass security defenses. The exploitation of the OPSWAT driver is a notable example of this trend, as it involves abusing a trusted piece of software to achieve malicious ends. This incident serves as a reminder for organizations and individuals, particularly those in the targeted region, to maintain robust security postures, ensure all software, including security tools and their components, is up-to-date with the latest patches, and to exercise caution when handling unsolicited files or links, regardless of their apparent legitimacy.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.