A multi-stage phishing campaign targeted Cambodian individuals and organizations with localized lures posing as government COVID-19 notices, public-health materials, real-estate documents, and dental records. Malicious archives delivered an Inno Setup executable that used a signed Tencent binary for DLL sideloading, extracted encrypted payloads concealed in PNG files, and injected the final payload—SparkRAT, an open-source Go-based remote-access trojan—into ctfmon.exe. The RAT was configured to communicate over TCP/443 with sx.nuihuw.com, with nuihuw.top identified as a backup command-and-control server.
The operators used the vulnerable OPSWAT AppRemover driver, ardrv.sys, in a bring-your-own-vulnerable-driver attack. Exploitation of CVE-2026-36425 enabled privilege elevation and termination of security-product processes, complementing persistence and defense-evasion measures. While the operation resembles reported Silver Fox tradecraft, researchers found no shared infrastructure, code reuse, or certificate overlap to substantiate that attribution; the cluster remains unattributed, with only low-confidence indications of Chinese-language development or deployment links.

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Acronis Threat Research Unit published technical details of the Cambodia-focused SparkRAT campaign, including its Cambodian COVID-19 lure, F7u00ex.exe/WfoY.qf DLL-sideloading chain, PNG-staged payloads, TaskHandler persistence, and abuse of ardrv.sys to terminate security processes. Acronis noted similarities to SilverFox-style activity but did not confirm attribution.
An unattributed cluster targeted individuals and organizations in Cambodia with Cambodia-themed phishing lures delivering SparkRAT. The multi-stage chain used Tencent DLL sideloading, PNG-hidden encrypted payloads, process injection, persistence, and the vulnerable OPSWAT AppRemover driver ardrv.sys (CVE-2026-36425) to impair security tools.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 33 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcetrojan-killer.net
Open sourcethehackernews.com
Open sourceacronis.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.