Spark RAT Campaign Used OPSWAT Driver to Blind Defenses
Acronis found a Cambodia-targeted Spark RAT campaign in artifacts collected from late June through early August 2026, and the chain used the vulnerable OPSWAT AppRemover driver ardrv.sys, tracked as CVE-2026-36425, to interfere with endpoint security before the RAT ran. The lures dressed the initial phishing stage as government notices, public health material, real estate records, and other local themes.
The malware does not need a custom kernel exploit. It loads a signed but flawed driver that Windows trusts, then uses that driver to terminate or weaken security processes, which can leave EDR and antivirus less able to see the payload or stop it in time. Acronis also said the loader checks for sandbox-like timing changes and looks for Huorong Internet Security before proceeding.
For defenders, the exposure sits at the trust boundary around signed drivers: if that load succeeds, a phishing victim can lose visibility before the remote-access trojan is present as a normal process. The reporting does not settle how widely the campaign spread, but it shows that endpoint protection may be suppressed before detection logic gets a clean shot at Spark RAT.