SparkRAT is an open-source, Go-based cross-platform remote access trojan (RAT) supporting Windows, Linux, and macOS. It provides remote command execution, system and host information collection, process and file management, file upload and download, screenshot capture, and payload retrieval. SparkRAT communicates with command-and-control infrastructure using configurable network settings; observed variants have used WebSocket, HTTP, HTTPS, and encrypted C2 communications. It also includes an update mechanism.
SparkRAT has been deployed by multiple unrelated intrusion sets and is not attributable to a single threat actor. Its consistent use was a defining feature of the DragonSpark activity cluster, which was assessed as operated by a Chinese-speaking actor targeting Internet-exposed web and MySQL servers in East Asia. Other observed campaigns have delivered it through trojanized VPN and software installers, Cambodia-themed document lures, malicious shortcut-file exploitation, and exploitation of vulnerable internet-facing remote-management and CI/CD infrastructure. SparkRAT has also been observed as a final in-memory payload following DLL sideloading and process injection. The tool is routinely used to establish interactive remote control, conduct reconnaissance, collect data, and support follow-on intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The driver is associated with OPSWAT AppRemover and is tracked as CVE-2026-36425, a local improper access-control issue in older ardrv.sys versions. In the Acronis case, the malware used the driver as a bring-your-own-vulnerable-driver step to terminate security-related processes, including Microsoft Defender components. | “SparkRAT is the final remote-access payload in a Cambodia-focused Windows campaign” and was “injected through later stages.”
Microsoft created a security patch for Windows systems to fix the vulnerability, giving it the CVE identifier CVE-2024-43451. The security patch was published on November 12th, 2024. | The other files detected exploiting the new vulnerability followed a similar attack scenario that ended with the installation of Redline Stealer malware. The similarity has two possible explanations: 1. One attacker using different types of malware (the initial file installs SparkRAT malware).
APT29 (Cozy Bear) exploited CVE-2024-27198 in real-world campaigns.
The vulnerability, tracked as CVE-2026-1731, is an operating system command injection flaw that also impacts some older versions of BeyondTrust Privileged Remote Access. The flaw allows an attacker to execute arbitrary commands on a server without the need for credentials or any user interaction. | A critical vulnerability in BeyondTrust Remote Support is facing an increase in threat activity, with hackers deploying SparkRAT and vShell backdoors and using remote management tools to conduct reconnaissance...
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The other files detected exploiting the new vulnerability followed a similar attack scenario that ended with the installation of Redline Stealer malware. The similarity has two possible explanations: 1. One attacker using different types of malware (the initial file installs SparkRAT malware).
The following public tools were observed on the victims’ network... SparkRAT.
Sandbox family search for family:sparkrat . Returned a per-victim SparkRAT sibling submitted independently to the sandbox. Its ldflags COMMIT differs from the case sample. Confirms the operator uses per-target SparkRAT builds.
...Leslieloader that downloads a backdoor dubbed SparkRAT. The Go variants are compliant with Windows, Linux and OSX. They support file upload and download, system fingerprinting and direct command-line interaction with infected hosts.
"...including CurlBack, SparkRAT, AresRAT, Xeno RAT, AllaKore, and ReverseRAT."
The attacks are characterized by the use of the little known open source SparkRAT and malware that attempts to evade detection through Golang source code interpretation.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
it seems that the threat actor attacked the development company and distributed installers with malware strains
CERT-UA shared technical information with ClearSky regarding the email sent to the target to launch the attack chain. The lure email message is sent from a Ukrainian government server. The message body includes a demand to renew the academic certificate, as the current certificate is allegedly about to expire.
Furthermore, the malware is registered in the task scheduler to ensure it will be executed even after system reboots.
"schtasks /create /tn \"TaskHandler\" /tr \"C:\Drivers\mQm\F7u00ex.exe\" /sc ONSTART /ru \"NT AUTHORITY\SYSTEM\" /rl HIGHEST"
It provides features to control the infected system such as executing commands
When examining the URL file, ClearSky’s team exposed a new vulnerability, unrelated to the two vulnerabilities mentioned above: Right clicking the file establishes a connection to an external server.
L'exploit permet à des acteurs malveillants de prendre le contrôle d'un système par un simple clic droit sur un fichier malveillant.
The vulnerability is exploited by generating a URL file that can be activated using the following non-standard actions: 1. A single right-click (in all versions of Windows). 2. Deleting the file by using the delete button (only in Windows 10/11). 3. Dragging the file to another folder.
Furthermore, the malware is registered in the task scheduler to ensure it will be executed even after system reboots.
"schtasks /create /tn \"TaskHandler\" /tr \"C:\Drivers\mQm\F7u00ex.exe\" /sc ONSTART /ru \"NT AUTHORITY\SYSTEM\" /rl HIGHEST"
Furthermore, the malware is registered in the task scheduler to ensure it will be executed even after system reboots.
"schtasks /create /tn \"TaskHandler\" /tr \"C:\Drivers\mQm\F7u00ex.exe\" /sc ONSTART /ru \"NT AUTHORITY\SYSTEM\" /rl HIGHEST"
The campaign included "process injection" and moved code through "vssvc.exe, ctfmon.exe and svchost.exe," with SparkRAT injected through later stages.
"ardrv.sys" is described as a vulnerable driver tracked as CVE-2026-36425, used as a "bring-your-own-vulnerable-driver step" to terminate security-related processes.
Then a file named Learn[.]cmd is dropped and executed. The CMD file includes commands encoded by adding garbage strings and using several variables that, when put together, create the commands.
The report identifies "PNG-staged payload files," including "56360VK1ES8.yvap," "BssBfeFFoA3A.nz," "cnV.rb," and "d7zzQhzRglBv.es."
The loader then extracts encrypted stages from several PNG-formatted files... It decrypts its embedded configuration using AES-CTR.
The campaign used an Inno Setup executable disguised as a Cambodian government document: "Cambodian Government Notice on COVID-19 Prevention and Control (July 7).docx.exe."
The campaign included "process injection" and moved code through "vssvc.exe, ctfmon.exe and svchost.exe," with SparkRAT injected through later stages.
The commands carried out by file Learn[.]cmd: • Tasklist[.]exe – listing all tasks running on the system. • findstr /I avastui.exe avgui.exe nswscsvc.exe sophoshealth.exe – checking for installed AV engines. • findstr /I "wrsa.exe opssvc.exe" – checking for additional security components.
La faille de sécurité « CVE-2024-43451 » est une vulnérabilité de divulgation de hash NTLM par usurpation d'identité, qui peut être exploitée pour voler le hash NTLMv2 de l'utilisateur connecté en le forçant à se connecter à un serveur distant contrôlé par un attaquant.
SparkRAT provides basic features commonly found in RAT malware, such as executing commands, stealing information, and controlling processes and files.
Information theft: including exfiltration of platform information (CPU, network, memory, disk, and system uptime information)
SparkRAT provides basic features commonly found in RAT malware, such as executing commands, stealing information, and controlling processes and files.
The commands carried out by file Learn[.]cmd: • Tasklist[.]exe – listing all tasks running on the system. • findstr /I avastui.exe avgui.exe nswscsvc.exe sophoshealth.exe – checking for installed AV engines. • findstr /I "wrsa.exe opssvc.exe" – checking for additional security components.
The malicious installer connects to the C&C server and downloads encrypted configuration data.
The decrypted configuration reveals the primary C2 server (sx.nuihuw.com), which communicates over port 443... [with] a backup C2 server, nuihuw.top.
When installed on a user’s system, it can perform a variety of malicious behaviors, such as executing commands remotely, controlling files and processes, downloading additional payloads
Microsoft researchers also identified a sample that can run on Windows based on a cross-platform (Linux, Windows, macOS) open-source remote administration tool (RAT) with various features such as managing processes, file operations, screenshotting, and running commands.
62 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
42 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
SparkRAT is the final remote-access implant in a Windows intrusion chain. The campaign uses an Inno Setup lure, PNG-staged payloads, DLL sideloading, process injection, TaskHandler task/service persistence, and the vulnerable ardrv.sys driver to terminate security processes, including Microsoft Defender components.
An open-source, cross-platform remote-access trojan written in Go. In this campaign it is reflectively loaded into ctfmon.exe, decrypts and validates its AES-CTR-protected configuration, and establishes C2 communications over TCP/443 with a primary and backup server.
Remote access trojan/backdoor deployed following exploitation of TeamCity vulnerabilities.
Remote access trojan observed in exploitation activity targeting a BeyondTrust critical vulnerability (CVE-2026-1731).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.