SparkRAT is an open-source remote administration tool written in Go that is abused as a remote access trojan. It supports Windows, Linux, and macOS and provides remote command execution, file and process management, payload downloading, screenshot capture, and system-information collection. It communicates with command-and-control servers over WebSocket and includes an automatic update mechanism. These functions enable remote control, information theft, and follow-on payload deployment.
SparkRAT has been deployed after exploitation of internet-facing enterprise applications, including Apache ActiveMQ through CVE-2023-46604, vulnerable JetBrains TeamCity servers, and BeyondTrust Remote Support and Privileged Remote Access through CVE-2026-1731. ActiveMQ exploitation delivering SparkRAT was observed as early as October 10, 2023, before public disclosure of the vulnerability. Other distribution methods include trojanized VPN installers that execute legitimate setup software alongside the malware and certificate-renewal phishing associated with UAC-0194 that exploited Windows vulnerability CVE-2024-43451. Windows deployments have established persistence through automatic-start services, scheduled tasks, and startup-folder execution.
SparkRAT is associated with the DragonSpark intrusion cluster targeting organizations in East Asia and has also appeared among tools used by Houken. An unattributed Cambodia-focused Windows campaign delivered it through document-themed lures and a multistage loading chain involving DLL sideloading, process injection, security-product impairment, and vulnerable-driver abuse. In that campaign, SparkRAT was reflectively loaded into a legitimate process. These loading and evasion mechanisms belong to the surrounding deployment chain rather than necessarily to SparkRAT itself. Its public availability and use across distinct campaigns preclude attribution of a SparkRAT infection to a single threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2023-46604 allows remote attackers with network access to a broker to execute arbitrary shell commands. This is achieved by exploiting serialized class types within the OpenWire protocol, which, in turn, leads to the broker instantiating any class available on the classpath.
Injection de commandes OS non authentifiée dans BeyondTrust Privileged Remote Access (PRA) et Remote Support, découverte par l’agent IA tiers Hacktron AI. Dans les 4 jours suivant la divulgation, un premier cluster de menaces l’exploitait ; 5 clusters supplémentaires dans les 7 jours. | Activités post-exploitation observées : élévation de privilèges, exfiltration de données, dépôt de payloads secondaires (SNOWLIGHT, SPARKRAT, cryptomineurs).
The driver is associated with OPSWAT AppRemover and is tracked as CVE-2026-36425, a local improper access-control issue in older ardrv.sys versions. In the Acronis case, the malware used the driver as a bring-your-own-vulnerable-driver step to terminate security-related processes, including Microsoft Defender components. | “SparkRAT is the final remote-access payload in a Cambodia-focused Windows campaign” and was “injected through later stages.”
Microsoft created a security patch for Windows systems to fix the vulnerability, giving it the CVE identifier CVE-2024-43451. The security patch was published on November 12th, 2024. | The other files detected exploiting the new vulnerability followed a similar attack scenario that ended with the installation of Redline Stealer malware. The similarity has two possible explanations: 1. One attacker using different types of malware (the initial file installs SparkRAT malware).
APT29 (Cozy Bear) exploited CVE-2024-27198 in real-world campaigns.
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The other files detected exploiting the new vulnerability followed a similar attack scenario that ended with the installation of Redline Stealer malware. The similarity has two possible explanations: 1. One attacker using different types of malware (the initial file installs SparkRAT malware).
The following public tools were observed on the victims’ network... SparkRAT.
Sandbox family search for family:sparkrat . Returned a per-victim SparkRAT sibling submitted independently to the sandbox. Its ldflags COMMIT differs from the case sample. Confirms the operator uses per-target SparkRAT builds.
...Leslieloader that downloads a backdoor dubbed SparkRAT. The Go variants are compliant with Windows, Linux and OSX. They support file upload and download, system fingerprinting and direct command-line interaction with infected hosts.
"...including CurlBack, SparkRAT, AresRAT, Xeno RAT, AllaKore, and ReverseRAT."
The attacks are characterized by the use of the little known open source SparkRAT and malware that attempts to evade detection through Golang source code interpretation.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
CVE-2026-1731, an unauthenticated OS command injection vulnerability in BeyondTrust Privileged Remote Access and Remote Support... Threat actors used it in targeted initial-access campaigns.
it seems that the threat actor attacked the development company and distributed installers with malware strains
CERT-UA shared technical information with ClearSky regarding the email sent to the target to launch the attack chain. The lure email message is sent from a Ukrainian government server. The message body includes a demand to renew the academic certificate, as the current certificate is allegedly about to expire.
Furthermore, the malware is registered in the task scheduler to ensure it will be executed even after system reboots.
"schtasks /create /tn \"TaskHandler\" /tr \"C:\Drivers\mQm\F7u00ex.exe\" /sc ONSTART /ru \"NT AUTHORITY\SYSTEM\" /rl HIGHEST"
It provides features to control the infected system such as executing commands
A cmd.exe process is spawned by java.exe out of the respective Apache ActiveMQ application folder.
When examining the URL file, ClearSky’s team exposed a new vulnerability, unrelated to the two vulnerabilities mentioned above: Right clicking the file establishes a connection to an external server.
The vulnerability is exploited by generating a URL file that can be activated using the following non-standard actions: 1. A single right-click (in all versions of Windows). 2. Deleting the file by using the delete button (only in Windows 10/11). 3. Dragging the file to another folder.
Furthermore, the malware is registered in the task scheduler to ensure it will be executed even after system reboots.
"schtasks /create /tn \"TaskHandler\" /tr \"C:\Drivers\mQm\F7u00ex.exe\" /sc ONSTART /ru \"NT AUTHORITY\SYSTEM\" /rl HIGHEST"
Furthermore, the malware is registered in the task scheduler to ensure it will be executed even after system reboots.
"schtasks /create /tn \"TaskHandler\" /tr \"C:\Drivers\mQm\F7u00ex.exe\" /sc ONSTART /ru \"NT AUTHORITY\SYSTEM\" /rl HIGHEST"
The campaign included "process injection" and moved code through "vssvc.exe, ctfmon.exe and svchost.exe," with SparkRAT injected through later stages.
The attackers escalated privileges, exfiltrated data and dropped payloads including SNOWLIGHT, SPARKRAT and cryptominers.
Then a file named Learn[.]cmd is dropped and executed. The CMD file includes commands encoded by adding garbage strings and using several variables that, when put together, create the commands.
The report identifies "PNG-staged payload files," including "56360VK1ES8.yvap," "BssBfeFFoA3A.nz," "cnV.rb," and "d7zzQhzRglBv.es."
The loader then extracts encrypted stages from several PNG-formatted files... It decrypts its embedded configuration using AES-CTR.
The campaign used an Inno Setup executable disguised as a Cambodian government document: "Cambodian Government Notice on COVID-19 Prevention and Control (July 7).docx.exe."
The campaign included "process injection" and moved code through "vssvc.exe, ctfmon.exe and svchost.exe," with SparkRAT injected through later stages.
The commands carried out by file Learn[.]cmd: • Tasklist[.]exe – listing all tasks running on the system. • findstr /I avastui.exe avgui.exe nswscsvc.exe sophoshealth.exe – checking for installed AV engines. • findstr /I "wrsa.exe opssvc.exe" – checking for additional security components.
SparkRAT provides basic features commonly found in RAT malware, such as executing commands, stealing information, and controlling processes and files.
SparkRAT spawns a child process of cmd ver (T1082 – System Information Discovery).
The commands carried out by file Learn[.]cmd: • Tasklist[.]exe – listing all tasks running on the system. • findstr /I avastui.exe avgui.exe nswscsvc.exe sophoshealth.exe – checking for installed AV engines. • findstr /I "wrsa.exe opssvc.exe" – checking for additional security components.
The malicious installer connects to the C&C server and downloads encrypted configuration data.
SparkRAT then sends a basic victim fingerprint back to its C2 via HTTP POST request ... (T1071.001 – Application Layer Protocol: Web Protocols).
The downloaded bat file obtains SparkRAT ... via certutil (T1105 – Ingress Tool Transfer).
Microsoft researchers also identified a sample that can run on Windows based on a cross-platform (Linux, Windows, macOS) open-source remote administration tool (RAT) with various features such as managing processes, file operations, screenshotting, and running commands.
66 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
49 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote-access trojan payload deployed in targeted initial-access campaigns exploiting the BeyondTrust command-injection flaw.
Identified as a remote access trojan and a secondary payload deployed following exploitation of CVE-2026-1731 in BeyondTrust Privileged Remote Access and Remote Support. Specific capabilities and direct exploitation of the vulnerability by SPARKRAT are not established in the content.
A named secondary payload deployed by threat clusters following exploitation of the BeyondTrust vulnerability CVE-2026-1731.
SparkRAT is the final remote-access implant in a Windows intrusion chain. The campaign uses an Inno Setup lure, PNG-staged payloads, DLL sideloading, process injection, TaskHandler task/service persistence, and the vulnerable ardrv.sys driver to terminate security processes, including Microsoft Defender components.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.