Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Spark RAT Exploits Vulnerable OPSWAT Driver to Disable Security Tools in Cambodia

Spark RAT is being used in Cambodia to abuse a vulnerable OPSWAT driver, disabling endpoint security and enabling data exfiltration. The incident underscores the need for continuous control monitoring and audit‑ready evidence of third‑party component health.

LiveThreat™ Intelligence · 📅 August 27, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
thehackernews.com

Spark RAT Exploits Vulnerable OPSWAT Driver to Disable Security Tools in Cambodia

What Happened — A new campaign delivering the open‑source Spark RAT is targeting individuals and organizations in Cambodia. The malware leverages a known vulnerability in the OPSWAT file‑scanning driver to disable endpoint security tools, allowing the RAT to maintain persistence and exfiltrate data.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates how an unpatched driver can create a control gap that defeats anti‑malware safeguards – a scenario SOC 2 Control CC6.1 (System Operations) expects continuous monitoring and evidence of remediation.
  • Highlights the need for continuous evidence collection on security‑tool health; Verisq’s Control Mapping capability can automatically capture driver‑integrity logs as audit‑ready proof.
  • Shows the importance of maintaining a defensible audit trail for third‑party components (e.g., OPSWAT) to satisfy vendor‑risk and security‑control requirements.

Who Is Affected — Government agencies, public‑sector entities, and private organizations in Cambodia that rely on OPSWAT or similar endpoint‑security drivers.

Recommended Actions

  • Inventory all OPSWAT drivers and verify they are patched to the latest version.
  • Map the driver‑integrity control to SOC 2 CC6.1 and enable continuous monitoring to capture tamper‑evidence.
  • Incorporate driver‑health logs into your evidence repository for audit readiness.
  • Conduct a focused risk assessment on third‑party security tools and update vendor‑management policies.

Source: The Hacker News

Technical Notes

  • Attack vector: exploitation of a vulnerable OPSWAT driver (no CVE disclosed).
  • Payload: Spark RAT, capable of credential theft, keylogging, and data exfiltration.
  • Lure themes: government notices, public‑health alerts, real‑estate offers, etc.
📰 Original Source
https://thehackernews.com/2026/08/spark-rat-targets-cambodia-abuses.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →