< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

Cybersecurity researchers report new malware campaigns targeting US, Israel, and Cambodia

Cybersecurity researchers have identified two distinct malware campaigns targeting different regions and objectives.

An Iranian-aligned threat actor known as Screening Serpens has expanded its espionage capabilities by deploying six new Remote Access Trojan (RAT) variants. The group utilizes sophisticated social engineering, including fraudulent recruitment platforms and fake job sites, to target high-value technology professionals in the United States, Israel, and the United Arab Emirates. The campaign aims to compromise sensitive intellectual property and national security interests through credential harvesting and lateral movement.

Separately, a campaign involving the open-source Spark RAT has been observed targeting individuals and organizations in Cambodia. This attack utilizes a ‘bring your own vulnerable driver’ (BYOVD) technique, exploiting a legitimate but vulnerable OPSWAT AppRemover driver to escalate privileges and disable security software. The malware is distributed via phishing emails using diverse lures such as government notices, public health materials, and real estate documents.

Entities

Acronis · OPSWAT · Screening Serpens · Tencent