Spark RAT Phish Hits Cambodia With “Official” Lures

The Hacker News · High sophistication
Last updated August 27, 2026

A real campaign targeting people and organizations in Cambodia uses phishing emails with localized “official-looking” themes to trick recipients into running an installer from a compressed file. Once executed, the malware chain deploys Spark RAT for remote control and uses a vulnerable OPSWAT driver to disable security tools like Microsoft Defender.

Key findings

  • Victims in Cambodia were targeted with phishing emails using multiple “lure themes” (government, health, real estate, promotions).
  • The phishing emails distributed “compressed archives” that included an installer designed to trick users into running it.
  • The infection chain ultimately deploys Spark RAT, enabling remote control of infected devices.
  • The malware uses a bring-your-own-vulnerable-driver (BYOVD) approach with an OPSWAT AppRemover driver to neutralize security software (e.g., Microsoft Defender).

Who’s being targeted

  • Commonly targeted roles: All employees, Administrative assistants, Government employees, Healthcare operations staff, Real estate staff, Executives (as approvers of process/verification policies).
  • Affected industries: Government, Healthcare/Public health, Real estate, General business (cross-industry).
  • Attack channels: email.
  • Impersonated: Cambodian government office or public health authority (theme-based impersonation).

Awareness takeaways

  • Treat unexpected “official” notices (government/health/real estate) that arrive as compressed attachments as suspicious, verify through a known, trusted channel before opening or running anything.
  • Never run installers/executables to view a document; legitimate organizations typically send PDFs or links to known portals, not Inno Setup installers in archives.
  • Report any suspicious email immediately, this campaign is designed to disable security tools after execution, reducing the chance that antivirus will protect you once you click.

Red flags to watch for

  • Unexpected compressed attachment that requires running an installer to view a “document”
  • Email uses broad, attention-grabbing official themes (government/health/real estate/promotions) to pressure action
  • Attachment contains an executable/installer rather than a normal PDF/Office document
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine an email: “[Government Notice] Document for your review” and it looks perfectly official, in Khmer, from a local office. You open the compressed attachment, but instead of a PDF, there’s an Inno Setup installer you’re told to run to see the document. That’s the Spark RAT trap. Run it, and behind the scenes Spark RAT installs, then abuses a vulnerable OPSWAT AppRemover driver to quietly shut down Microsoft Defender and other protection on your machine. If an “official” email sends a compressed file and tells you to run an installer to view a document, stop and report it to security, don’t run it, ever.

Similar attacks

Invoice Phish Drops ValleyRAT via BYOVD Drivers

Invoice Phish Drops ValleyRAT via BYOVD Drivers

Researchers reported a real campaign by the China-based Silver Fox group against a Japanese industrial manufacturer. The attack starts with an invoice-themed phishing message that leads victims to open a ZIP file, triggering a DLL sideloading chain and installing ValleyRAT for persistent remote…

July 30, 2026
Fake Claude App and Alert Apps Drive New Scams

Fake Claude App and Alert Apps Drive New Scams

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude desktop app, a fake emergency alert app, and banking-malware phishing). The common pattern is “looks normal, feels urgent,” leading users to…

July 23, 2026
APT28 Uses Diplomatic Word Lures to Drop HOOKEDGE

APT28 Uses Diplomatic Word Lures to Drop HOOKEDGE

Researchers report real-world campaigns targeting European government and diplomatic organizations using diplomatic-themed Microsoft Word documents. Victims are prompted to click “Enable Content,” which runs malicious macros that install the HOOKEDGE backdoor and connect to webhook-based…

August 28, 2026
Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Researchers say the North Korea-linked Lazarus group ran “Operation Dream Job,” posing as recruiters and sending fake job offers to lure targets into downloading trojanized PDF tools and opening booby-trapped PDFs. The campaign focused largely on defense-related organizations and used both a…

August 12, 2026
Lazarus “Dream Job” Lures Spread Zero-Day Attack

Lazarus “Dream Job” Lures Spread Zero-Day Attack

Check Point and Microsoft report North Korea’s Lazarus Group used a long-running “Dream Job” social engineering campaign to target defense-sector job seekers with fake employer sites and trojanized documents/software. Victims were lured into opening malicious PDFs or installing a modified PDF…

August 11, 2026
Zero-Click Zimbra Webmail Phish Hits NATO Sectors

Zero-Click Zimbra Webmail Phish Hits NATO Sectors

Researchers at Unit 42 reported a real espionage campaign targeting organizations using Zimbra webmail, including government, defense, transportation and financial sectors. The attackers sent “zero-click” phishing emails disguised as news headlines, where opening/viewing the message could trigger a…

July 23, 2026