< Back to all clusters
[TECHNOLOGY] · Cambodia · 3 sources

started · updated

Cambodia warns of rising Telegram malware and account theft

Cambodian authorities have issued an urgent warning regarding a surge in malware infections and Telegram account thefts across the country. The Ministry of Post and Telecommunications confirmed that attackers are using deceptive files—disguised as routine documents, photos, or government notices—to compromise users.

One identified campaign utilizes a multi-stage infection chain that employs fake COVID-19 prevention notices as bait. Once a user opens the malicious file, the software can exploit driver vulnerabilities to disable antivirus programs and install SparkRAT, an open-source remote access trojan. This tool allows attackers to remotely control infected devices, capture screens, log keystrokes, and steal passwords for platforms like Telegram and Facebook.

Minister Chea Vandeth advised users to avoid opening or running files with extensions such as .exe, .bat, .vbs, .ps1, .sh, .msi, or .scr. The Ministry of Interior noted that while these tactics are not new, the high volume of Telegram usage has increased the frequency of these attacks, some of which appear to originate from overseas.

Entities

Cambodia · Chea Vandeth · Ministry of Interior · Ministry of Post and Telecommunications