Threat Intelligence

New Malware Campaign Disables Security Software Using a Trusted Driver

The Hacker News · 27 Aug 2026
Key Takeaway Keep all software and drivers updated, be cautious of unexpected documents or notices from unfamiliar sources, and ensure your endpoint protection includes defences against driver-based attacks.

A new cyberattack campaign is targeting individuals and organizations in Cambodia with a remote access trojan (RAT) called Spark RAT. Researchers found that attackers are using a variety of convincing lures—including fake government notices, public health information, and real estate content—to trick victims into opening malicious files.

Once installed, the malware exploits a vulnerable driver from security vendor OPSWAT to disable antivirus and endpoint protection tools on the infected device. This technique, known as 'Bring Your Own Vulnerable Driver' (BYOVD), allows attackers to bypass security software by abusing legitimate, signed drivers rather than relying on their own malicious code, making detection harder.

While this campaign currently appears focused on Cambodia, the tactics used—social engineering lures and driver-based security bypass—are increasingly common globally and could be adapted for other regions, including Australia. Small businesses should be aware that even trusted software components can be weaponized by attackers.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.