A recent malware campaign in Cambodia employs multi-stage tactics to deliver SparkRAT, a remote access trojan. The campaign targets individuals and organizations using phishing lures disguised as government and health documents. Key details include:
- **Attack Method**: Malware hides in PNG files and installs a vulnerable driver (ardrv.sys) that terminates antivirus processes. It utilizes DLL sideloading and a Bring Your Own Vulnerable Driver (BYOVD) strategy.
- **Final Payload**: SparkRAT is loaded into ctfmon.exe, allowing full remote control. Command and control servers are linked to domains like sx.nuihuw.com.
- **Attribution**: No clear attribution exists, but tactics resemble those of the SilverFox group associated with Chinese cyber activity.
- **Recommendations for Defenders**: Block listed C2 domains, search for the ardrv.sys driver, and monitor for suspicious tasks like "TaskHandler."