A real campaign targeting people and organizations in Cambodia uses phishing emails with localized “official-looking” themes to trick recipients into running an installer from a compressed file. Once executed, the malware chain deploys Spark RAT for remote control and uses a vulnerable OPSWAT driver to disable security tools like Microsoft Defender.
Key findings
- Victims in Cambodia were targeted with phishing emails using multiple “lure themes” (government, health, real estate, promotions).
- The phishing emails distributed “compressed archives” that included an installer designed to trick users into running it.
- The infection chain ultimately deploys Spark RAT, enabling remote control of infected devices.
- The malware uses a bring-your-own-vulnerable-driver (BYOVD) approach with an OPSWAT AppRemover driver to neutralize security software (e.g., Microsoft Defender).
Who’s being targeted
- Commonly targeted roles: All employees, Administrative assistants, Government employees, Healthcare operations staff, Real estate staff, Executives (as approvers of process/verification policies).
- Affected industries: Government, Healthcare/Public health, Real estate, General business (cross-industry).
- Attack channels: email.
- Impersonated: Cambodian government office or public health authority (theme-based impersonation).
Awareness takeaways
- Treat unexpected “official” notices (government/health/real estate) that arrive as compressed attachments as suspicious, verify through a known, trusted channel before opening or running anything.
- Never run installers/executables to view a document; legitimate organizations typically send PDFs or links to known portals, not Inno Setup installers in archives.
- Report any suspicious email immediately, this campaign is designed to disable security tools after execution, reducing the chance that antivirus will protect you once you click.
Red flags to watch for
- Unexpected compressed attachment that requires running an installer to view a “document”
- Email uses broad, attention-grabbing official themes (government/health/real estate/promotions) to pressure action
- Attachment contains an executable/installer rather than a normal PDF/Office document
Read the video transcript
Imagine an email: “[Government Notice] Document for your review” and it looks perfectly official, in Khmer, from a local office. You open the compressed attachment, but instead of a PDF, there’s an Inno Setup installer you’re told to run to see the document. That’s the Spark RAT trap. Run it, and behind the scenes Spark RAT installs, then abuses a vulnerable OPSWAT AppRemover driver to quietly shut down Microsoft Defender and other protection on your machine. If an “official” email sends a compressed file and tells you to run an installer to view a document, stop and report it to security, don’t run it, ever.