Spark RAT is an open-source, Go-based cross-platform remote access trojan (RAT) for Windows, Linux, and macOS. It provides operators remote control of compromised systems. It has been deployed in targeted operations against Cambodian individuals and organizations, including phishing campaigns using localized government, public-health, real-estate, and promotional lures. Observed Windows delivery chains have used archive-contained installers, DLL side-loading, encrypted staged payloads, process injection, persistence mechanisms, and vulnerable-driver abuse to impair endpoint security before executing the RAT. Spark RAT has also been observed in operations associated with RedNovember (Storm-2077), Cyber Anarchy Squad, and FamousSparrow activity, as well as activity attributed to SideCopy targeting sectors in India. RedNovember operations using Spark RAT targeted government and private-sector organizations across multiple regions, including defense, aerospace, and legal-services entities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The campaign installs the OPSWAT AppRemover "ardrv.sys" driver, which is vulnerable to CVE-2026-36425, to terminate security-related processes including Microsoft Defender, Huorong Internet Security, and Tencent PC Manager. | Individuals and organizations in Cambodia have emerged as the target of a new campaign that delivers an open-source remote access trojan (RAT) called Spark RAT.
Threat actors have been observed exploiting a recently disclosed critical security flaw impacting BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) products... The vulnerability, tracked as CVE-2026-1731 (CVSS score: 9.9), allows attackers to execute operating system commands in the context of the site user... Unit 42 said it detected the security flaw being actively exploited in the wild... CISA ... KEV ... confirm that the bug has been exploited in ransomware campaigns.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A loader for a version of the open-source Spark RAT that was modified to include code from an open-source Go shellcode loader.
...compromise of vulnerable VPNs, firewalls, and other security solutions with Pantegana and Spark RAT...
13 distinct techniques documented for this family, organized by ATT&CK tactic.
"Threat actors have been observed exploiting ... CVE-2026-1731 ... allows attackers to execute operating system commands in the context of the site user... leverage the affected 'thin-scc-wrapper' script that's reachable via WebSocket interface to inject and execute arbitrary shell commands"
The payload performs the following sequence of actions - Attempt to patch AMSI and ETW related functionality; Setup persistence using a scheduled task.
The inject mode works by parsing and decrypting shellcode embedded in another PNG file from the archive, and then injecting it into 'vssvc.exe'... A fourth PNG-based payload file... [is] injected into 'ctfmon.exe,' ultimately leading to the execution of Spark RAT.
In the next stage, it decrypts shellcode concealed within a PNG file present in the archive to run a second stager.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An open-source, Go-based remote-access trojan deployed through a multi-stage phishing and DLL side-loading chain. It provides attackers remote control of compromised devices; the campaign uses a vulnerable driver to escalate privileges and disable security products.
An open-source, Go-based, cross-platform remote-access trojan that enables remote control of compromised devices. In this campaign, it is delivered through phishing archives and a multi-stage DLL sideloading and BYOVD chain that disables security tooling, establishes persistence, and injects payloads into Windows processes.
A remote access trojan referenced as one of multiple malware families used by the adversary in attacks targeting sectors in India.
Deployed following exploitation of CVE-2026-1731 as part of an intrusion chain involving web shells, C2, lateral movement, and data theft—consistent with a remote access trojan used to maintain interactive control of compromised environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.