Cambodia-Focused Malware Campaign Uses Multi-Stage Infection Chain and SparkRAT

Summary
Acronis researchers analyzed a Cambodia-focused campaign that uses DLL sideloading, payloads hidden in PNG files, and a vulnerable driver to impair security tools before deploying SparkRAT. Attribution to SilverFox remains unconfirmed.
Key points
- The researchers assess the campaign as Cambodia-focused based mainly on archive names and lures, including government notices, health materials, dental records, and real estate documents. They did not observe the delivery email or confirm whether the activity is ongoing.
- The infection chain starts with an Inno Setup executable that drops components into a hidden directory and sideloads a malicious DLL through a signed Tencent binary.
- Malware stages are extracted and decrypted from PNG-formatted files, then injected into Windows processes including vssvc.exe, ctfmon.exe, and svchost.exe.
- The malware establishes persistence with a Windows service and scheduled task, attempts to patch AMSI and ETW, adds Microsoft Defender exclusions, and terminates security-product processes.
- It uses the vulnerable OPSWAT AppRemover driver ardrv.sys, affected by CVE-2026-36425, to terminate processes through a BYOVD technique.
- The final payload is SparkRAT, configured to communicate with sx.nuihuw.com over port 443 and use nuihuw.top:443 as a backup endpoint.
- The campaign shares techniques with SilverFox-associated activity, but researchers found no definitive actor link and assess possible Chinese-language development or deployment links with low confidence. Acronis says its EDR/XDR detects and blocks the threat.
Article Details
- Attack Vectors
- The analyzed archive contained a COVID-19-themed executable disguised with a .docx.exe filename. A targeted-phishing delivery scenario is plausible, but the researchers did not observe delivery telemetry.
- An Inno Setup installer dropped components into a hidden C:\Drivers directory and launched a signed Tencent Corporation executable that sideloaded the malicious DLL WfoY.qf.
- The loader extracted encrypted payloads from PNG-formatted files. Later stages decrypted and injected code into vssvc.exe, ctfmon.exe, and svchost.exe.
- The malware established persistence through a TaskHandler Windows service and a scheduled task of the same name.
- Defense impairment included attempts to patch AMSI and ETW, Microsoft Defender exclusions, security-process termination, and observed use of a vulnerable ardrv.sys driver.
- The final stage reflectively loaded SparkRAT into ctfmon.exe. Its configuration specified a primary and backup C2 server on port 443.
- Defensive Notes
- Acronis reported that Acronis EDR/XDR detected and blocked the threat.
- The observed TaskHandler service and scheduled task, Defender exclusions, ardrv.sys installation, and termination of security processes are investigation points.
- Additional vulnerable drivers appeared in payload strings, but their deployment was not confirmed.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | nuihuw[.]top | Backup SparkRAT C2 server configured for port 443. |
| HOSTNAME | sx[.]nuihuw[.]com | Primary SparkRAT C2 server; communication was observed over port 443. |
| SHA256 | 03d763330b711c6c933883e6cc9e11b8ba2eac3845b01798beddaef998b2c017 | Hash of another archive listed as connected to the activity. |
| SHA256 | 0a050e1d5338b936037f0928039c26893a553c3170b16b82bf75a9113b34a52f | SHA-256 of the lure-themed installer listed in the IOC section. |
| SHA256 | 0f0f06669c4bf4d222384b23766b93fb2f8a370047af50a8d5009564959f6171 | SHA-256 of the 56360VK1ES8.yvap payload container. |
| SHA256 | 14eae85f027a94dbd1814f0925c5ec541ba8dfe6a850ab4004cfc95d67a1516d | SHA-256 of the cnV.rb payload container. |
| SHA256 | 2b676d28b2fdcc062ae6a3c1dd590001c9f80a417a510cc2ebbfe25c33cc020a | Hash of another archive listed as connected to the activity. |
| SHA256 | 2e5e5f7590bd34fd6883cc488243f24d536a0b9f27f63c64420052471c58ecaf | Hash of another archive listed as connected to the activity. |
| SHA256 | 37c463e9d3e629e29699bf65279b9996dd5efb88921d57d2892fc33ef6efec25 | Hash of another archive listed as connected to the activity. |
| SHA256 | 4088200eb4e87a335ab600f14c22d8f7305f8a2a7e58e825e789f69ba2bf1f93 | Hash of another archive listed as connected to the activity. |
| SHA256 | 49a53cd161508c5fd690575b013f1b484db77ee94a4adf2bbd52e08418097f0f | Hash of another archive listed as connected to the activity. |
| SHA256 | 541fedb12cd4fa6a21be87c244f3ef09b7ab8e6e3031fd090f4848989854deca | Hash of another archive listed as connected to the activity. |
| SHA256 | 54f3e991b892f61dfa67143d319a6a0fedf19a9c9f9bef2cba72becebfad2b2c | Hash of another archive listed as connected to the activity. |
| SHA256 | 5512d1e7545adf6af071698cd3d0124e2044bb670eef761179a2d14ad2bbda5a | Hash of another archive listed as connected to the activity. |
| SHA256 | 603247ade94f89f46d781b707fad7a73f959a7ea6553e1447753e52a2ea4b694 | SHA-256 of the BssBfeFFoA3A.nz payload container. |
| SHA256 | 61a061293a2d872267a08ff66e57d3e01113fd0a395be6661960e69d15a7cca3 | SHA-256 of the d7zzQhzRglBv.es payload container. |
| SHA256 | 635c9cccbc247c655971f8c7efb05e7418707614b1b2baa9c07cada7ece75ea6 | Hash of another archive listed as connected to the activity. |
| SHA256 | 6adb46283b92308d57b32cd5c442f6b7852b960235265d97b2f6b4ea7b4635d3 | Hash of another archive listed as connected to the activity. |
| SHA256 | 6c1c3e7b3ba87781f34c047b28418f7745a9c3ad45eb9a7ec00da8a9893e6bd7 | Hash of another archive listed as connected to the activity. |
| SHA256 | 7504887e1e195ad585cffa5b6a5034161a7cc49f351123d60def79302bdb8326 | SHA-256 of the vulnerable ardrv.sys driver deployed by the malware. |
| SHA256 | 7ef1757e773270f5f0799797861290097a202dc1fe7a1eab13373d8a132da0d0 | SHA-256 of the malicious sideloaded DLL WfoY.qf. |
| SHA256 | 8009e75fcb20fb1faa0f13f4d4f1cd3d5eff2ed025e0f81a1da9ea31d93e0dee | Hash of another archive listed as connected to the activity. |
| SHA256 | 8b39e5b5ab169ba07eec0d9c421d07ae96df4a16cc2f93f4ca0d521bdb3164bb | Hash of another archive listed as connected to the activity. |
| SHA256 | 91ddd3c7a02138fc033a3337245a6adc9f8a5aeb4953f07e689c119b40d7dfaa | Hash of another archive listed as connected to the activity. |
| SHA256 | d0c13e5b3c097143129e6d2bfc698570f3f2c0325cc2b0a1dacbacbf87f25330 | Hash of another archive listed as connected to the activity. |
| SHA256 | d8b0b96a9afd7a81807e225ae9979438ecf53a02c87995dac31723308d05722c | Hash of another archive listed as connected to the activity. |
| SHA256 | dd12a110462803cc2f930b6f53920c391e1e50424dfb64e084649d7124ff8d82 | Hash of another archive listed as connected to the activity. |
| SHA256 | dedd917feb42d18a3d0b927d4bcfadd5248a7291a76ad43d502087b5c23c7b89 | Hash of another archive listed as connected to the activity. |
| SHA256 | f7b9ab6c6d46b9b82c9c5a4deebf2f77ef1cbfffe2bf11c5c412f9f4f416d9ab | SHA-256 of the analyzed archive listed in the IOC section. |
| SHA256 | fc664ae8c0efe751bb05bca24d5ff0f9295bd85d4e70d1f64f687c8b17002ca7 | Hash of another archive listed as connected to the activity. |
MITRE ATT&CK
T1036.007 · Double File ExtensionThe lure-themed installer used a .docx.exe filename to appear to be a document.T1053.005 · Scheduled TaskThe malware created an ONSTART scheduled task named TaskHandler to run F7u00ex.exe as SYSTEM.T1055 · Process InjectionDecrypted stages were injected into vssvc.exe, ctfmon.exe, and svchost.exe.T1134.001 · Token Impersonation/TheftWhen not already running as SYSTEM, the loader accessed the winlogon.exe SYSTEM token for impersonation.T1140 · Deobfuscate/Decode Files or InformationMultiple stages decrypted embedded payloads extracted from PNG-formatted files at runtime.T1211 · Exploitation for StealthThe malware invoked the vulnerable IOCTL in ardrv.sys and successfully terminated processes as part of its defense-impairment operation.T1497.003 · Time Based ChecksThe loader checked elapsed sleep time and terminated if timing suggested a manipulated analysis environment.T1543.003 · Windows ServiceThe malware created and started an auto-start TaskHandler Windows service to run F7u00ex.exe.T1562.001 · Disable or Modify ToolsStages attempted to patch AMSI and ETW, added Microsoft Defender exclusions, and terminated security-product processes, including through a vulnerable driver.T1574.002 · DLL Side-LoadingThe signed F7u00ex.exe executable sideloaded the malicious WfoY.qf DLL.T1620 · Reflective Code LoadingThe stage injected into ctfmon.exe reflectively loaded the embedded SparkRAT PE into memory.
CVE
Threat Actors
Malware
Vendors
AcronisAcronis’ Threat Research Unit (TRU) identified a recent campaign focused on Cambodia. The analyzed archives, discovered while hunting for related activity, use several lure themes, including Cambodian governmentMicrosoftAfter creating another persistence mechanism, it configures Microsoft Defender exclusions by adding registry entries and adding exclusions for VSSVC.exe, ctfmon.exe, C:\Drivers, and C:\Windows\System32 directory.OPSWATThe vulnerable driver ardrv.sys, associated with OPSWAT AppRemover, is affected by the vulnerability tracked as CVE-2026-36425. The campaign abuses the vulnerable driver as part of its BYOVD technique to impair securityQihoo 360Qihoo 360 is a major Chinese cybersecurity vendor, making its presence particularly relevant when assessing malware targeting Chinese and broader East Asian environments.Tencent CorporationThe executable F7u00ex.exe is a signed binary associated with Tencent Corporation and is used to sideload the malicious DLL WfoY.qf.
Products
360 Total Security360 total security process check and injection to vssvc.exeIf none of the listed processes are found, it will instead create a Windows Service that will continuously run the executable F7u00ex.exe as its persistenceAcronis EDR/XDRThis threat has been detected and blocked by Acronis EDR/XDR:Huorong Internet Securitypayload file pathBefore reading the PNG file, the loader first checks processes related to Huorong Internet Security a lightweight, Chinese-developed antivirus and endpoint-security product widely used in China,Inno SetupDiscovered similar samples ITWThe analyzed campaign begins with an Inno Setup executable and when executed, it performs a multi-stage attack chain that includes DLL sideloading, anti-analysis checks, token manipulation,Microsoft DefenderAfter creating another persistence mechanism, it configures Microsoft Defender exclusions by adding registry entries and adding exclusions for VSSVC.exe, ctfmon.exe, C:\Drivers, and C:\Windows\System32 directory.OPSWAT AppRemoverThe vulnerable driver ardrv.sys, associated with OPSWAT AppRemover, is affected by the vulnerability tracked as CVE-2026-36425. The campaign abuses the vulnerable driver as part of its BYOVD technique to impair securityTencent PC ManagerAV-related processes from 360 Total Security, Huorong Internet Security, Microsoft Defender, and Tencent PC Manager.