Observed attack chain of the campaign | Image: Acronis’ Threat Research Unit
At a Glance
| Actor/Group | Unattributed cluster; low-confidence overlap with SilverFox-associated activity |
| Activity | Multi-stage malware campaign delivering SparkRAT via phishing lures and BYOVD |
| Targets | Individuals and organizations in Cambodia |
| Scale | Similar samples seen in the wild from late June through early August 2026 |
| Status | No law-enforcement action; tracked as an active research cluster |
| Source | Acronis Threat Research Unit (TRU) |
TL;DR
A new Cambodia malware campaign hides its payloads inside PNG image files and installs a vulnerable driver to disable antivirus. The final stage drops SparkRAT, an open-source remote access trojan, giving operators full remote control. Acronis TRU found the activity resembles SilverFox tradecraft but stopped short of naming a culprit.
What Happened
Acronis’ Threat Research Unit uncovered the campaign while hunting related activity. The lures target Cambodian users directly. Themes include government notices, public health announcements, dental records, and real estate documents.
One sample poses as a COVID-19 notice. Its filename reads “Cambodian Government Notice on COVID-19 Prevention and Control (July 7).docx.exe”. The double extension hides an Inno Setup installer. Once run, it drops files into a hidden C:\Drivers folder.
The infection chain is long and layered. It uses DLL sideloading through a signed Tencent binary. It then decrypts shellcode hidden inside PNG files. As Acronis notes, each component handles “a specific part of the attack.”
How the Attack Impairs Defenses
This Cambodia malware campaign works hard to blind security tools. It patches AMSI and ETW to dodge inspection. It adds Microsoft Defender exclusions for its own files and folders.
The centerpiece is a Bring Your Own Vulnerable Driver attack. The malware installs ardrv.sys, a driver tied to OPSWAT AppRemover. That driver carries the flaw tracked as CVE-2026-36425. The bug lets a local user terminate processes through IOCTL 0x2420031 without proper privilege checks.
Using that kernel access, the malware kills antivirus processes. Its targets include 360 Total Security, Huorong Internet Security, Microsoft Defender, and Tencent PC Manager. Internal log strings like “huorong detected, blinding” reveal the intent plainly.
The Final Payload: SparkRAT
The last stage reflectively loads SparkRAT into ctfmon.exe, a trusted Windows process. SparkRAT is an open-source RAT written in Go, publicly released in 2022. Hiding it inside a legitimate process helps the malware avoid notice.
The RAT phones home to sx.nuihuw.com over port 443. A backup server, nuihuw.top, keeps it running if the primary fails. Its config also holds a Chinese-language note field meaning “Default”.
Who Is Behind It
Attribution stays open. The campaign shares tactics with SilverFox, a China-linked cluster. Both use DLL sideloading, vulnerable drivers, and multi-stage delivery.
Even so, Acronis found no hard link. Investigators saw no shared infrastructure, no code reuse, and no matching certificates. The report also notes this campaign drops SparkRAT rather than the ValleyRAT payload usually tied to SilverFox. Acronis tracks it as “an unattributed cluster with possible Chinese-language development or deployment links,” assessed with low confidence.
Impact and What Comes Next
The true victim count is unclear. Acronis based its targeting call on archive names and Cambodia-related subjects. Similar samples appeared in the wild across roughly six weeks, but the team could not confirm the campaign is still active.
Defenders should act now. Block the listed C2 domains and hunt for the ardrv.sys driver. Watch for suspicious services or scheduled tasks named “TaskHandler”. Cambodia’s rising role as a regional flashpoint makes continued China-linked activity likely. Treating BYOVD driver abuse as a priority threat remains wise.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!