"The samples employ diverse lure themes, suggesting an effort to appeal to a broad range of potential victims," Acronis Threat Research Unit researchers Darrel Virtusio and Subhajeet Singha wrote, summarizing an attack cluster that Acronis found delivering the open-source Spark RAT to targets in Cambodia.
Delivery chain: Inno Setup installer, signed Tencent DLL sideloading, and PNG-hidden shellcode
Acronis analysts describe a multi-stage infection chain that begins with phishing emails delivering compressed archives. Recipients are lured into running an Inno Setup executable. That installer triggers a DLL side-loading sequence using a legitimately signed Tencent executable, which then drops interim payloads. These payloads extract multiple PNG files from the archive; each PNG conceals encrypted shellcode that is decrypted and executed in later stages.
BYOVD abuse of ardrv.sys (CVE-2026-36425) to disable security tools
Notably, the campaign employs a bring-your-own-vulnerable-driver (BYOVD) technique to load a legitimate-but-vulnerable driver associated with OPSWAT AppRemover—"ardrv.sys"—and thereby escalate privileges and neutralize security software. Acronis states the installer attempts to install the ardrv.sys driver, which is vulnerable to CVE-2026-36425, and then uses that capability to terminate processes belonging to Microsoft Defender, Huorong Internet Security, and Tencent PC Manager.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildAnti-analysis checks and explicit targeting of Chinese-language security products
The DLL loader performs a timing-based anti-sandbox check: it measures elapsed sleep delays and aborts if the timing falls outside expected ranges, a common technique to evade automated analysis environments. The loader also enumerates running processes for Huorong Internet Security ("HipsTray.exe") and, if present, attempts to weaken that product's privileges. Later stages check for a list of hard-coded processes associated with Qihoo 360 before proceeding with persistence and execution. Acronis notes the Spark RAT configuration contains a Chinese-language value and observes that the malware targets several security products commonly used in Chinese-speaking environments.
Two execution modes, persistence mechanisms, and process injection into vssvc.exe and ctfmon.exe
The payload chooses one of two modes depending on its privilege level. If already running as SYSTEM, it enters "inject mode" and bypasses persistence to parse and inject shellcode into vssvc.exe. That injected payload monitors the vssvc.exe instance and re-injects shellcode if the process terminates or restarts. If not running as SYSTEM, the payload enters "setup mode," establishes persistence—either a Windows service-based launcher or a scheduled task—and then proceeds to inject the shellcode into vssvc.exe. Separately, a fourth PNG-derived payload is decrypted and injected into ctfmon.exe, which leads to the execution of Spark RAT, a Go-based cross-platform open-source remote access trojan that enables remote control of compromised devices.
Attribution: operational overlaps with Silver Fox but insufficient evidence
Acronis documents a set of operational parallels to the Silver Fox ecosystem—references to other drivers (including those tied to TrueSight and Zemana Anti-Malware SDK), DLL sideloading with a signed application, multi-stage payload delivery, persistence via Windows services and scheduled tasks, and efforts to create Microsoft Defender exclusions. The targeting of Huorong processes has also been observed in past Silver Fox-related activity. However, Acronis says there is not enough evidence to attribute the campaign to Silver Fox: the analysis found no shared infrastructure, no function-level code reuse, and no matching certificates. A concrete differentiator is the payload choice; Silver Fox operations have used custom payloads such as ValleyRAT, while the activity here drops the open-source Spark RAT. Acronis therefore tracks the activity as an unattributed cluster with possible Chinese-language development or deployment links and explicitly rates that assessment as low confidence.
How technologists, policymakers, and affected organizations should view this activity
- Technologists and security teams: expect layered tradecraft—DLL sideloading of signed binaries, PNG-embedded shellcode, timing-based anti-sandbox checks, and BYOVD using ardrv.sys (CVE-2026-36425). Watch for scheduled tasks and unexpected Windows services, monitor vssvc.exe and ctfmon.exe for signs of injection, and review process lists for attempts to terminate security products including Microsoft Defender, Huorong, and Tencent PC Manager.
- Policymakers and regulators: the activity blends commodity open-source tooling with privilege-escalation techniques tied to a known vulnerable driver, raising questions about driver vetting and disclosure practices for CVE-2026-36425. Acronis’s low-confidence attribution and the presence of Chinese-language values in the configuration may be relevant to cross-border reporting and investigative priorities.
- Affected enterprises and procurement leaders: the campaign underscores the need to inventory third-party security products (Huorong, Qihoo 360, Tencent PC Manager) and verify whether mitigations exist for CVE-2026-36425. Because the campaign uses broad lure themes—government notices, public health, real estate, dental records, promotions—user-facing controls and phishing-resistance measures remain important.
Acronis discovered multiple malicious artifacts between late June and early August 2026, though it is unclear whether the campaign remains ongoing. The operation combines commodity open-source RAT code with sophisticated delivery and privilege-escalation techniques; without additional code, infrastructure, or certificate ties, its authorship remains an open question. Observers should watch for further artifacts or reuse that would convert the current low-confidence assessment into firmer attribution.




