Spark RAT Exploits Vulnerable OPSWAT Driver to Disable Security Tools in Cambodia
What Happened — A new campaign delivering the open‑source Spark RAT is targeting individuals and organizations in Cambodia. The malware leverages a known vulnerability in the OPSWAT file‑scanning driver to disable endpoint security tools, allowing the RAT to maintain persistence and exfiltrate data.
Why It Matters for Compliance & Audit Readiness
- Demonstrates how an unpatched driver can create a control gap that defeats anti‑malware safeguards – a scenario SOC 2 Control CC6.1 (System Operations) expects continuous monitoring and evidence of remediation.
- Highlights the need for continuous evidence collection on security‑tool health; Verisq’s Control Mapping capability can automatically capture driver‑integrity logs as audit‑ready proof.
- Shows the importance of maintaining a defensible audit trail for third‑party components (e.g., OPSWAT) to satisfy vendor‑risk and security‑control requirements.
Who Is Affected — Government agencies, public‑sector entities, and private organizations in Cambodia that rely on OPSWAT or similar endpoint‑security drivers.
Recommended Actions
- Inventory all OPSWAT drivers and verify they are patched to the latest version.
- Map the driver‑integrity control to SOC 2 CC6.1 and enable continuous monitoring to capture tamper‑evidence.
- Incorporate driver‑health logs into your evidence repository for audit readiness.
- Conduct a focused risk assessment on third‑party security tools and update vendor‑management policies.
Source: The Hacker News
Technical Notes
- Attack vector: exploitation of a vulnerable OPSWAT driver (no CVE disclosed).
- Payload: Spark RAT, capable of credential theft, keylogging, and data exfiltration.
- Lure themes: government notices, public‑health alerts, real‑estate offers, etc.