Acronis' Threat Research Unit identified a recent campaign targeting individuals and organizations in Cambodia. The analyzed samples employ diverse lure themes suggesting an effort to appeal to a broad range of potential victims, including government notices, public health materials, real estate-related content, and other topics. The campaign employs a multi-stage infection chain including DLL sideloading, decryption of shellcodes hidden in PNG files, process injection, and installation of vulnerable drivers.
The final stage reflectively loads SparkRAT into a legitimate Windows process, providing the operators with remote access and control while concealing execution within a trusted process. The campaign shows operational similarities to SilverFox-associated activity but no shared infrastructure, code reuse, or other actor-specific link was identified. The analyzed campaign uses a multi-stage execution chain with each component handling a specific part of the attack.[/subscribe_to_unlock_form]
Acronis' Threat Research Unit identified a recent campaign targeting individuals and organizations in Cambodia. The analyzed samples employ diverse lure themes suggesting an effort to appeal to a broad range of potential victims, including government notices, public health materials, real estate-related content, and other topics. The campaign employs a multi-stage infection chain including DLL sideloading, decryption of shellcodes hidden in PNG files, process injection, and installation of vulnerable drivers.
The final stage reflectively loads SparkRAT into a legitimate Windows process, providing the operators with remote access and control while concealing execution within a trusted process. The campaign shows operational similarities to SilverFox-associated activity but no shared infrastructure, code reuse, or other actor-specific link was identified. The analyzed campaign uses a multi-stage execution chain with each component handling a specific part of the attack.[emaillocker id="1283"]
An Inno Setup package creates a hidden staging directory, launches a signed Tencent executable, and relies on DLL sideloading to start the malicious loader. The loader then extracts encrypted stages from several PNG-formatted files and moves execution into a malicious executable, a malicious executable, and a malicious executable. Persistence and defense impairment are built into multiple stages.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1566.002 | Phishing | Spearphishing Link |
| Execution | T1059.003 | Command and Scripting Interpreter | Windows Command Shell |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Defence Evasion | T1027.002 | Obfuscated Files or Information | Software Packing |
| Defence Evasion | T1055 | Process Injection | - |
| Collection | T1005 | Data from Local System | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
The following reports contain further technical details:
[/emaillocker]