A coordinated cyber campaign is targeting individuals and organizations across Cambodia, pairing an open-source remote access trojan with a legitimately signed OPSWAT kernel driver to bypass endpoint defenses. According to reporting from The Hacker News and analysis by Acronis Threat Research, threat actors are deploying the Spark RAT alongside the vulnerable component, effectively weaponizing a trusted system utility to disable security software and establish persistent access.

The operation relies on a “bring your own vulnerable driver” (BYOVD) methodology. Rather than developing custom zero-day exploits, attackers are repurposing the publicly available Spark RAT framework and coupling it with a digitally signed OPSWAT kernel driver. Because the driver carries a valid cryptographic signature, Windows loads it with kernel-level privileges. Once active, the payload leverages these permissions to terminate or interfere with competing security agents before the RAT establishes its foothold.

Unlike highly targeted espionage operations, this campaign employs a high-volume, broad-spectrum social engineering strategy. Attackers distribute malicious payloads through a wide array of localized document templates, including government directives, public health advisories, real estate listings, and commercial notices. This volume-over-precision approach indicates an intent to maximize initial access across both public and private sectors, prioritizing localized relevance over narrow industry profiling.

The campaign underscores a structural vulnerability in modern endpoint security: an over-reliance on cryptographic signatures at the expense of runtime behavioral analysis. By pairing easily accessible open-source malware with legitimate, signed binaries, threat actors have significantly lowered the barrier to professional-grade system compromise. Static, signature-based controls are increasingly ineffective against these threats, as the underlying binaries are technically legitimate and the payloads are trivially modified.

In response, security teams should prioritize runtime behavioral telemetry and hardware-backed code integrity verification. Organizations are advised to audit and restrict third-party kernel drivers, implementing strict allowlisting for system-utility vendors like OPSWAT. Security awareness programs should also be updated to address broad-spectrum document lures, training personnel to verify sources across public affairs, health, and commercial contexts rather than relying on familiar branding or file extensions.

As open-source attack frameworks mature and legitimate software supply chains face continued exploitation, the Spark RAT campaign highlights the necessity of shifting from reactive detection to proactive, behavior-centric security architectures. Defenders must operate on the assumption that trusted binaries will be weaponized and design endpoint controls accordingly.


一項有組織的網絡攻擊行動正針對柬埔寨境內的個人及機構,將開源遠端存取木馬(RAT)與經合法數碼簽章的 OPSWAT kernel driver 配對,以繞過端點防禦。據 The Hacker News 報道及 Acronis Threat Research 分析,威脅行為者正部署 Spark RAT 並結合該存在漏洞的組件,實質上將受信任的系統工具武器化,用以停用安全軟件並建立持久存取權限。

該行動依賴「Bring Your Own Vulnerable Driver」(BYOVD)手法。攻擊者並未開發自訂的 zero-day exploits,而是重用公開的 Spark RAT 框架,並將其與經數碼簽章的 OPSWAT kernel driver 結合。由於該 kernel driver 具備有效的數碼簽章,Windows 會以核心層級權限將其載入。一旦啟動,payload 便會利用此等權限終止或干擾其他安全軟件,隨後 RAT 才建立立足點。

與高度針對性的間諜行動不同,此攻擊行動採用大規模、廣譜的社交工程策略。攻擊者透過大量本地化文件範本分發惡意 payload,內容涵蓋政府指令、公共衛生通告、房地產列表及商業通知等。這種「重數量輕精準」的手法顯示其意圖在公營及私營機構中最大化 initial access,優先依賴本地化關聯性,而非針對特定行業的分析。

此行動突顯了現代端點安全的結構性弱點:過度依賴數碼簽章,卻犧牲了 runtime behavioral analysis。透過將易於取得的開源惡意軟件與合法、已簽署的 binaries 結合,威脅行為者大幅降低了達成專業級系統入侵的門檻。靜態、基於簽章的控制措施對此類威脅日益失效,因為底層 binaries 在技術上屬合法,而 payload 亦只需輕微修改即可。

作為應對,安全團隊應優先採用 runtime behavioral telemetry 及 hardware-backed code integrity verification。建議機構審計並限制第三方 kernel drivers,並為 OPSWAT 等系統工具供應商實施嚴格的 allowlisting。此外,網絡安全意識培訓計劃亦須更新,以應對廣譜文件誘餌,培訓員工在公共事務、衛生及商業情境中核實來源,而非依賴熟悉的品牌或檔案副檔名。

隨著開源攻擊框架日益成熟,以及合法軟件供應鏈持續遭濫用,Spark RAT 攻擊行動凸顯了從被動偵測轉向主動、以行為為核心的安全架構的必要性。防禦者必須假設受信任的 binaries 將遭武器化,並據此設計端點控制措施。

新聞來源 / Original News Source