Spark RAT campaign hits Cambodia, using fake government and health notices as bait
A new wave of attacks aimed at Cambodian targets is spreading Spark RAT, an open-source remote access tool, through lures dressed up as official documents and property listings.

Key points
- A new campaign targeting people and organisations in Cambodia is spreading Spark RAT, an open-source remote access tool that lets attackers take over infected computers.
- The lures include fake government notices, public health materials and real estate content, according to Acronis researchers.
- The attackers also abuse a vulnerable driver from security vendor OPSWAT to switch off antivirus and other protections on infected machines.
- Spark RAT is freely available on code-sharing sites, which makes it hard to tie the activity to any single criminal group.
- Victims in Cambodia span multiple sectors, and no ransom demand has been reported in this campaign.
A fresh malware campaign is hitting computers in Cambodia, and the bait is designed to look boringly official.
Researchers at Acronis say the attackers are dropping a piece of malicious software called Spark RAT, a remote access trojan. A remote access trojan, or RAT, is a program that quietly hands control of a victim's computer to someone else on the internet. Once installed, the attacker can read files, watch the screen, turn on the microphone, and run further commands.
Spark RAT is not a custom-built weapon. It is an open-source tool anyone can download, which is part of why it keeps turning up in different criminal operations around the world.
Who is being targeted?
People and organisations inside Cambodia. Acronis describes a spread of lures aimed at different kinds of victim rather than one specific industry.
The bait documents include fake government notices, public health materials, real estate listings and other everyday topics. The mix suggests the attackers are casting a wide net and hoping some percentage of recipients open the file. The campaign was first written up by The Hacker News.
How does the attack actually work?
A target opens what looks like a normal document, and the malware is quietly installed in the background. From there, Spark RAT phones home to a server run by the attackers and waits for orders.
Before settling in, the intruders take an extra step: they switch off the computer's security software. They do this by abusing a vulnerable driver made by OPSWAT, a well-known security vendor. A driver is a small piece of code that talks directly to the guts of the operating system. Because drivers run with very high privileges, a flawed one can be turned into a skeleton key. The attackers load the trusted-but-buggy OPSWAT driver, then use its weakness to shut down antivirus and endpoint protection tools that would normally raise the alarm.
This trick has a name in the industry: "bring your own vulnerable driver." Criminals like it because the driver itself is signed and legitimate, so Windows accepts it without complaint.
What is Spark RAT and who uses it?
Spark RAT is a free, cross-platform remote administration tool published on public code repositories. It was originally pitched as a legitimate admin utility. In practice it has been picked up by a range of criminal crews because it works, it is free, and it is easy to modify.
That also makes attribution hard. Anyone from a lone operator to a state-linked group can grab the code, so pointing at a single culprit for the Cambodia campaign is not yet possible.
| Detail | What we know |
|---|---|
| Malware | Spark RAT (open-source remote access trojan) |
| Target region | Cambodia |
| Lure themes | Government notices, public health, real estate |
| Extra trick | Abuses a vulnerable OPSWAT driver to disable security tools |
| Reported by | Acronis Threat Research |
Should ordinary people worry?
If you live or work in Cambodia, treat unexpected documents with suspicion, especially ones that claim to come from a ministry, a health authority or a property agent. Do not open attachments from senders you cannot verify by phone or in person.
On the corporate side, security teams should hunt for the OPSWAT driver being loaded on machines where it has no business running. That single behaviour is often the loudest signal that this attack chain is unfolding.



