Spark RAT Targets Cambodia, Exploiting OPSWAT Vulnerability to Disable Security Tools
A sophisticated malware campaign has been uncovered targeting Cambodian organizations, utilizing a vulnerable driver from OPSWAT to disable security tools and gain unfettered access to compromised systems. Spark RAT, as the malware is known, exploits a previously undisclosed vulnerability in OPSWAT’s MetaAccess driver, which is used by several popular security software solutions.
The affected organizations are mostly based in Cambodia, with reports suggesting that government institutions and financial entities have been targeted. The attackers seem to be exploiting a remote access trojan (RAT) infection vector, using social engineering tactics to gain initial access to the compromised systems. Once inside, Spark RAT leverages its ability to disable security tools, including endpoint detection and response (EDR), antivirus software, and intrusion detection systems (IDS).
Spark RAT’s mechanism of operation involves exploiting a vulnerability in the OPSWAT MetaAccess driver, which is used by several prominent security vendors, such as Symantec and Kaspersky. The malware takes advantage of this weakness to disable the security tools, creating an environment conducive for further exploitation and lateral movement within the compromised network. This allows the attackers to maintain persistence and conceal their activities from security monitoring solutions.
The significance of this incident lies in the fact that OPSWAT’s MetaAccess driver is widely used across various industries, including finance, government, and healthcare. The vulnerability exploited by Spark RAT raises concerns about the potential for widespread compromise if left unpatched. This highlights the importance of regular security software updates and patch management, as well as the need for robust incident response planning to mitigate the impact of such attacks.
The use of a vulnerable driver as an attack vector is particularly concerning due to its implications on supply chain security. The OPSWAT MetaAccess driver’s widespread adoption across multiple industries creates a single point of failure that can be exploited by attackers, compromising not only individual organizations but also the entire ecosystem. As cybersecurity threats continue to evolve and become more sophisticated, it is essential for organizations to prioritize vulnerability management, adhere to strict patching schedules, and maintain robust security controls.
To minimize the risk of similar attacks, we recommend that readers take immediate action: ensure all OPSWAT MetaAccess driver versions are up-to-date and patched against known vulnerabilities. Regularly review and update security software, including EDR and antivirus solutions, to prevent potential exploitation. Moreover, implement a comprehensive incident response plan to quickly detect and respond to security incidents, thereby limiting the damage caused by such attacks.
Source: The Hacker News — 2026-08-27