Cambodia-Focused Malware Campaign Uses Multi-Stage Infection Chain and SparkRAT

· Original article ↗

Summary

Acronis researchers analyzed a Cambodia-focused campaign that uses DLL sideloading, payloads hidden in PNG files, and a vulnerable driver to impair security tools before deploying SparkRAT. Attribution to SilverFox remains unconfirmed.

Key points

  • The researchers assess the campaign as Cambodia-focused based mainly on archive names and lures, including government notices, health materials, dental records, and real estate documents. They did not observe the delivery email or confirm whether the activity is ongoing.
  • The infection chain starts with an Inno Setup executable that drops components into a hidden directory and sideloads a malicious DLL through a signed Tencent binary.
  • Malware stages are extracted and decrypted from PNG-formatted files, then injected into Windows processes including vssvc.exe, ctfmon.exe, and svchost.exe.
  • The malware establishes persistence with a Windows service and scheduled task, attempts to patch AMSI and ETW, adds Microsoft Defender exclusions, and terminates security-product processes.
  • It uses the vulnerable OPSWAT AppRemover driver ardrv.sys, affected by CVE-2026-36425, to terminate processes through a BYOVD technique.
  • The final payload is SparkRAT, configured to communicate with sx.nuihuw.com over port 443 and use nuihuw.top:443 as a backup endpoint.
  • The campaign shares techniques with SilverFox-associated activity, but researchers found no definitive actor link and assess possible Chinese-language development or deployment links with low confidence. Acronis says its EDR/XDR detects and blocks the threat.

Article Details

Attack Vectors
  • The analyzed archive contained a COVID-19-themed executable disguised with a .docx.exe filename. A targeted-phishing delivery scenario is plausible, but the researchers did not observe delivery telemetry.
  • An Inno Setup installer dropped components into a hidden C:\Drivers directory and launched a signed Tencent Corporation executable that sideloaded the malicious DLL WfoY.qf.
  • The loader extracted encrypted payloads from PNG-formatted files. Later stages decrypted and injected code into vssvc.exe, ctfmon.exe, and svchost.exe.
  • The malware established persistence through a TaskHandler Windows service and a scheduled task of the same name.
  • Defense impairment included attempts to patch AMSI and ETW, Microsoft Defender exclusions, security-process termination, and observed use of a vulnerable ardrv.sys driver.
  • The final stage reflectively loaded SparkRAT into ctfmon.exe. Its configuration specified a primary and backup C2 server on port 443.
Defensive Notes
  • Acronis reported that Acronis EDR/XDR detected and blocked the threat.
  • The observed TaskHandler service and scheduled task, Defender exclusions, ardrv.sys installation, and termination of security processes are investigation points.
  • Additional vulnerable drivers appeared in payload strings, but their deployment was not confirmed.

Indicators of compromise

TypeIndicatorContext
DOMAINnuihuw[.]topBackup SparkRAT C2 server configured for port 443.
HOSTNAMEsx[.]nuihuw[.]comPrimary SparkRAT C2 server; communication was observed over port 443.
SHA25603d763330b711c6c933883e6cc9e11b8ba2eac3845b01798beddaef998b2c017Hash of another archive listed as connected to the activity.
SHA2560a050e1d5338b936037f0928039c26893a553c3170b16b82bf75a9113b34a52fSHA-256 of the lure-themed installer listed in the IOC section.
SHA2560f0f06669c4bf4d222384b23766b93fb2f8a370047af50a8d5009564959f6171SHA-256 of the 56360VK1ES8.yvap payload container.
SHA25614eae85f027a94dbd1814f0925c5ec541ba8dfe6a850ab4004cfc95d67a1516dSHA-256 of the cnV.rb payload container.
SHA2562b676d28b2fdcc062ae6a3c1dd590001c9f80a417a510cc2ebbfe25c33cc020aHash of another archive listed as connected to the activity.
SHA2562e5e5f7590bd34fd6883cc488243f24d536a0b9f27f63c64420052471c58ecafHash of another archive listed as connected to the activity.
SHA25637c463e9d3e629e29699bf65279b9996dd5efb88921d57d2892fc33ef6efec25Hash of another archive listed as connected to the activity.
SHA2564088200eb4e87a335ab600f14c22d8f7305f8a2a7e58e825e789f69ba2bf1f93Hash of another archive listed as connected to the activity.
SHA25649a53cd161508c5fd690575b013f1b484db77ee94a4adf2bbd52e08418097f0fHash of another archive listed as connected to the activity.
SHA256541fedb12cd4fa6a21be87c244f3ef09b7ab8e6e3031fd090f4848989854decaHash of another archive listed as connected to the activity.
SHA25654f3e991b892f61dfa67143d319a6a0fedf19a9c9f9bef2cba72becebfad2b2cHash of another archive listed as connected to the activity.
SHA2565512d1e7545adf6af071698cd3d0124e2044bb670eef761179a2d14ad2bbda5aHash of another archive listed as connected to the activity.
SHA256603247ade94f89f46d781b707fad7a73f959a7ea6553e1447753e52a2ea4b694SHA-256 of the BssBfeFFoA3A.nz payload container.
SHA25661a061293a2d872267a08ff66e57d3e01113fd0a395be6661960e69d15a7cca3SHA-256 of the d7zzQhzRglBv.es payload container.
SHA256635c9cccbc247c655971f8c7efb05e7418707614b1b2baa9c07cada7ece75ea6Hash of another archive listed as connected to the activity.
SHA2566adb46283b92308d57b32cd5c442f6b7852b960235265d97b2f6b4ea7b4635d3Hash of another archive listed as connected to the activity.
SHA2566c1c3e7b3ba87781f34c047b28418f7745a9c3ad45eb9a7ec00da8a9893e6bd7Hash of another archive listed as connected to the activity.
SHA2567504887e1e195ad585cffa5b6a5034161a7cc49f351123d60def79302bdb8326SHA-256 of the vulnerable ardrv.sys driver deployed by the malware.
SHA2567ef1757e773270f5f0799797861290097a202dc1fe7a1eab13373d8a132da0d0SHA-256 of the malicious sideloaded DLL WfoY.qf.
SHA2568009e75fcb20fb1faa0f13f4d4f1cd3d5eff2ed025e0f81a1da9ea31d93e0deeHash of another archive listed as connected to the activity.
SHA2568b39e5b5ab169ba07eec0d9c421d07ae96df4a16cc2f93f4ca0d521bdb3164bbHash of another archive listed as connected to the activity.
SHA25691ddd3c7a02138fc033a3337245a6adc9f8a5aeb4953f07e689c119b40d7dfaaHash of another archive listed as connected to the activity.
SHA256d0c13e5b3c097143129e6d2bfc698570f3f2c0325cc2b0a1dacbacbf87f25330Hash of another archive listed as connected to the activity.
SHA256d8b0b96a9afd7a81807e225ae9979438ecf53a02c87995dac31723308d05722cHash of another archive listed as connected to the activity.
SHA256dd12a110462803cc2f930b6f53920c391e1e50424dfb64e084649d7124ff8d82Hash of another archive listed as connected to the activity.
SHA256dedd917feb42d18a3d0b927d4bcfadd5248a7291a76ad43d502087b5c23c7b89Hash of another archive listed as connected to the activity.
SHA256f7b9ab6c6d46b9b82c9c5a4deebf2f77ef1cbfffe2bf11c5c412f9f4f416d9abSHA-256 of the analyzed archive listed in the IOC section.
SHA256fc664ae8c0efe751bb05bca24d5ff0f9295bd85d4e70d1f64f687c8b17002ca7Hash of another archive listed as connected to the activity.

MITRE ATT&CK

CVE

Threat Actors

Malware

Vendors

Products

Countries

Related Articles