Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools
Summary
A new campaign is targeting individuals and organizations in Cambodia with an open-source remote access trojan (RAT) named Spark RAT. The attackers are using various lure themes, such as government notices and public health materials, to entice potential victims.
IFF Assessment
FOE
This article reports on a new malware campaign that is actively targeting a specific region, which is bad news for defenders.
Defender Context
This campaign highlights the ongoing threat of RATs being used in targeted attacks. Defenders should be aware of the diverse lure themes being employed and ensure robust endpoint protection and user awareness training are in place to mitigate the risk of infection from social engineering tactics.