CuraSec

Plan active

Spark RAT Campaign Abuses Vulnerable OPSWAT Driver via BYOVD in Cambodia

2026-08-27 21:01 UTC · The Hacker News · read the source ↗ #byovd#rat#edr-evasion
  • Engineer — Learn: The BYOVD technique exploiting a vulnerable OPSWAT driver to kill security tools is a notable evasion class worth understanding, but current targeting is regionally focused on Cambodia with no enrichment signals (no KEV, no PoC, no high EPSS) to justify immediate action in most environments.
  • SOC/IR — Plan: Build or tune detections for vulnerable OPSWAT driver loads and anomalous security-tool process terminations consistent with BYOVD; Spark RAT is open-source and signatures should be available to add to EDR and SIEM rule sets this quarter.
  • Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.