Acronis Threat Research Unit Discovers Campaign Targeting Cambodia Featuring Multi-Stage Attack Chain

Acronis Threat Research Unit discovered a recent cyberattack aimed at individuals and organizations in Cambodia. The cyberattack features a series of Cambodia themed lures such as government notices, public health announcements, dental records, real estate documentation and promotional offers designed to deceive a potential victim into clicking on malicious files. Researchers discovered similar samples in the wild from late June to early August, even though the status of the campaign at this time is unknown.

Multi-stage techniques employed by the malware include DLL sideloading, hidden encrypted files, process injection, and disabling security software. Finally, the malware deploys a remote access trojan known as SparkRAT on the victim’s computer giving attackers full control over a compromised machine.

How the attack works

In order to compromise a target, the campaign uses a malicious installer posing as a Cambodian government notice. When executed, the malware creates hidden files and deploys a legitimate signed Tencent executable file to load malicious code. The malware proceeds by checking for the presence of any security software on the infected device and attempts to disable any security mechanisms in place.

Further, malware embeds additional payloads in PNG files and injects malicious code into legitimate Windows processes, while also creating additional services and scheduled tasks for persistence.

Vulnerable driver exploited by the malware

One of the notable findings identified by Acronis is a vulnerable Windows driver called ardrv.sys linked to OPSWAT AppRemover. This driver is vulnerable to the CVE-2026-36425 exploit and was used by the malware to terminate processes belonging to security solutions, including Microsoft Defender and other security products.

SparkRAT used to control infected systems

The final payload used by the campaign is the open-source remote access trojan called SparkRAT, which is loaded in a legitimate Windows process allowing attackers to remotely maintain access to the victim’s computer, as well as hiding malicious activities. The malware was configured to connect to the attacker’s server over port 443.

Similar to SilverFox, but no known connection

Several similarities have been observed between this threat and the activities of SilverFox before, such as using DLL sideloading, process injection, persistence, exploiting vulnerable drivers to disable security products. However, there is no sufficient information to establish a direct connection with the SilverFox campaign.

This activity has been assessed as low confidence and is being tracked by Acronis as a separate cluster that could possibly be developed or deployed in Chinese language.


Acronis Protection

This threat has been identified and neutralized by Acronis EDR/XDR. Acronis has shared indicators of compromise such as sample hashes, malware components, and C2 infrastructure used in this activity.

Author