Acronis TRU reports malware tactics Australian MSPs need to watch

0

Acronis’ Threat Research Unit (TRU) says it has identified a malware campaign that illustrates techniques defenders should expect to see more often, including Bring Your Own Vulnerable Driver (BYOVD), DLL sideloading, process injection and encrypted payloads hidden inside image files.

While the activity used Cambodia-themed lures, the company said the tradecraft reflects broader trends relevant to security teams internationally, including managed service providers (MSPs). In the campaign, attackers were observed abusing a vulnerable driver, ardrv.sys (CVE-2026-36425), before deploying SparkRAT, an open-source remote access trojan.

In a technical write-up shared with media, TRU said the infection chain included an Inno Setup executable that created a hidden staging directory (C:\Drivers), dropped additional components, and used a signed Tencent binary to sideload a malicious DLL. Later stages extracted encrypted data from PNG files and moved execution into legitimate Windows processes including vssvc.exe, ctfmon.exe and svchost.exe.

TRU’s summary said the campaign demonstrated multiple persistence and defense-evasion measures, including creating Windows services and scheduled tasks, patching AMSI and ETW-related functionality, and adding Microsoft Defender exclusions. It also described process-termination activity targeting security products including Microsoft Defender, Tencent PC Manager, Huorong Internet Security and 360 Total Security.

According to the report, the driver ardrv.sys is associated with OPSWAT AppRemover and is affected by CVE-2026-36425, which TRU said enables process termination requests without adequate privilege validation. The malware was observed invoking a vulnerable IOCTL to terminate processes, consistent with BYOVD tactics designed to weaken endpoint protections.

The final payload was identified as SparkRAT, which TRU described as an open-source, cross-platform remote access trojan written in Go and released publicly in 2022. TRU reported the malware communicated with sx[.]nuihuw[.]com over port 443, with nuihuw[.]top also listed as a backup endpoint.

On attribution, TRU said the campaign shared operational characteristics with activity previously reported under “SilverFox”, including sideloading via signed applications, multi-stage delivery, persistence through services and scheduled tasks, Defender exclusions, and use of vulnerable drivers to terminate security tools. However, it said it did not identify shared infrastructure, code reuse, or other actor-specific links, and is tracking the activity as an unattributed cluster with possible Chinese-language development or deployment links, assessed with low confidence.

For Australian MSPs and enterprise defenders, the report points to a continued shift in attacker focus towards stealth, persistence and defence evasion, including weaponising trusted components and legitimate drivers to disable security controls before deploying remote-access tooling.

Share.

Comments are closed.

Visit Us On TwitterVisit Us On FacebookVisit Us On LinkedinVisit Us On Youtube