Affected Systems
Organizations and individuals in Cambodia. Campaign abuses vulnerable OPSWAT AppRemover driver (ardrv.sys, CVE-2026-36425) via BYOVD technique. Targets systems running Microsoft Defender, Huorong Internet Security, Tencent PC Manager, and Qihoo 360. Active timeframe: late June through early August 2026.
Exploitation Status
Active exploitation confirmed. Campaign observed delivering Spark RAT (open-source Go-based RAT) between late June and early August 2026. Exploits CVE-2026-36425 in OPSWAT ardrv.sys driver to disable security tools. Ongoing campaign status unclear as of report date.
Business Impact
Attackers gain full remote control of compromised systems via Spark RAT. Multi-stage attack chain uses DLL side-loading, anti-sandbox checks, AMSI/ETW patching, and privilege escalation to SYSTEM. Security products are actively disabled via vulnerable driver exploitation, leaving endpoints unprotected. Persistence established through Windows services and scheduled tasks. Possible links to Silver Fox threat actor ecosystem, though attribution remains low confidence. Primary risk to Cambodia-based organizations and users of Chinese security products.
Urgency
đźź Within 24 hours
Recommended Actions
- Block or quarantine OPSWAT AppRemover driver ardrv.sys (vulnerable to CVE-2026-36425) across endpoints using EDR or application control policies
- Hunt for Inno Setup executables delivered via phishing, signed Tencent binaries used for DLL side-loading, and suspicious PNG files containing encrypted shellcode
- Monitor for shellcode injection into vssvc.exe and ctfmon.exe processes, service creation with unusual binaries, and scheduled tasks pointing to recently dropped executables
- Review Windows Defender exclusions and service configurations for unauthorized modifications; check for disabled AMSI and ETW functionality
- Inspect network traffic for Spark RAT C2 communications; review endpoint logs for process termination of security tools (HipsTray.exe, 360-related processes, Defender)
---
# Geopolitical Context
Geopolitical Context
Cambodia has emerged as the target of a sophisticated cyber campaign deploying Spark RAT, an open-source remote access trojan, through phishing operations using diverse lures including government notices, public health materials, and real estate content. The campaign, active between late June and early August 2026, employs advanced techniques including bring-your-own-vulnerable-driver (BYOVD) methods to disable security tools. The operation exhibits tactical similarities to Silver Fox threat activity, including targeting of Chinese security products (Huorong, Qihoo 360, Tencent PC Manager) and multi-stage DLL sideloading chains. However, researchers assess with low confidence that this represents a distinct cluster, noting the use of open-source tooling rather than custom malware, absence of shared infrastructure, and lack of code reuse. The malware configuration contains Chinese-language values and targets security products common in Chinese-speaking environments, suggesting possible Chinese-language development or deployment links. Cambodia's position as a focal point for regional great power competition—particularly between China and Western interests—makes it a strategic target for intelligence collection operations.
State Actor Alignment
No definitive state actor attribution has been established. Researchers track this as an "unattributed cluster with possible Chinese-language development or deployment links" based on linguistic artifacts and targeting of Chinese security products. Operational similarities to the Silver Fox threat actor ecosystem exist, including targeting overlaps, DLL sideloading techniques, multi-stage delivery, and focus on Huorong security processes. However, key differentiators include absence of shared infrastructure, lack of function-level code reuse, different code-signing certificates, and deployment of open-source Spark RAT rather than custom payloads like ValleyRAT/Winos 4.0 typically associated with Silver Fox. The assessment remains low confidence pending additional technical, infrastructure, or victimology evidence. No sanctions or formal government attributions are currently associated with this activity.
Business Impacty pro region
This campaign underscores Cambodia's vulnerability as a target for cyber espionage operations in Southeast Asia. The broad lure themes—government notices, public health materials, real estate documents—suggest intelligence collection objectives spanning government, civil society, and commercial sectors. For regional security, the operation highlights several concerning trends: the proliferation of BYOVD techniques exploiting legitimate drivers (CVE-2026-36425 in OPSWAT's ardrv.sys) to bypass endpoint security; the accessibility of capable open-source RATs lowering barriers for sophisticated operations; and the targeting of security products common in Chinese-speaking environments, which may indicate regional operational focus. Cambodia's deepening economic and political ties with China, combined with ongoing Western concerns about governance and human rights, create a complex threat landscape where multiple state and non-state actors may seek intelligence access. The campaign's timing and scope may reflect broader regional intelligence priorities related to Cambodia's strategic position within ASEAN and along critical infrastructure corridors including Belt and Road Initiative projects.
Forecast
If this activity represents a distinct operational cluster rather than Silver Fox evolution, it may indicate emerging threat actors adopting proven Chinese-language tradecraft while leveraging open-source tooling to complicate attribution. If additional infrastructure or code overlaps with known Chinese-nexus groups are identified, confidence in state-linked attribution would increase. The exploitation of CVE-2026-36425 is likely to proliferate among other threat actors given the public disclosure and effectiveness of BYOVD techniques against endpoint security products. Organizations in Cambodia and broader Southeast Asia should anticipate continued targeting through localized phishing lures, particularly those mimicking government communications. If geopolitical tensions in the region intensify—particularly around South China Sea disputes, ASEAN alignment, or major infrastructure projects—Cambodia may experience increased cyber espionage activity from multiple state-aligned actors seeking strategic intelligence. Defensive measures should prioritize driver vulnerability management, enhanced email security, and monitoring for DLL sideloading chains targeting Chinese security products common in the region.
