Spark RAT is an open-source remote-access trojan written in Go that supports Windows, Linux, and macOS. It provides operators with remote control of compromised devices and a range of commands for controlling the target system. Its publicly available code has been adopted and modified by multiple threat actors for post-compromise access.
Spark RAT has been deployed through phishing and spearphishing, malicious installers, and exploitation of vulnerable infrastructure. A campaign targeting individuals and organizations in Cambodia used government, public-health, and real-estate lures to deliver compressed archives containing Inno Setup installers. Its Windows deployment chain combined DLL side-loading through a signed Tencent executable, encrypted shellcode concealed in PNG files, and process injection. Supporting components established Windows-service and scheduled-task persistence, performed anti-sandbox checks, attempted to impair security products, and abused a vulnerable OPSWAT AppRemover driver for privilege escalation and security-process termination. These behaviors belong to the deployment chain rather than necessarily to the unmodified Spark RAT codebase.
Users of Spark RAT include FamousSparrow, which deployed a modified version; SideCopy, in attacks against Indian sectors; Cyber Anarchy Squad, targeting Russia and Belarus; and Storm-2077, also tracked as RedNovember, TAG-100, and UNK_ColtCentury. Storm-2077 activity has included targeting government, defense, aerospace, legal-services, and semiconductor organizations. Actors associated with BianLian and Jasmin have also distributed Spark RAT through exploitation of the TeamCity authentication-bypass vulnerability CVE-2024-27198.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2024-27198 is a critical authentication bypass vulnerability identified within the web component of JetBrains TeamCity versions before 2023.11.4. This vulnerability enables remote unauthenticated attackers to circumvent authentication checks by crafting specific URLs. | Actors associated with the BianLian and Jasmin ransomware families have weaponized the vulnerability to distribute payloads such as the XMRig cryptocurrency miner and Spark RAT.
The campaign installs the OPSWAT AppRemover "ardrv.sys" driver, which is vulnerable to CVE-2026-36425, to terminate security-related processes including Microsoft Defender, Huorong Internet Security, and Tencent PC Manager. | Individuals and organizations in Cambodia have emerged as the target of a new campaign that delivers an open-source remote access trojan (RAT) called Spark RAT.
Threat actors have been observed exploiting a recently disclosed critical security flaw impacting BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) products... The vulnerability, tracked as CVE-2026-1731 (CVSS score: 9.9), allows attackers to execute operating system commands in the context of the site user... Unit 42 said it detected the security flaw being actively exploited in the wild... CISA ... KEV ... confirm that the bug has been exploited in ransomware campaigns.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The file Ntmssvc.dll is described as a “Modified Spark RAT.” | The Ntmssvc.dll sample is described as a "Modified Spark RAT."
...compromise of vulnerable VPNs, firewalls, and other security solutions with Pantegana and Spark RAT...
14 distinct techniques documented for this family, organized by ATT&CK tactic.
"Threat actors have been observed exploiting ... CVE-2026-1731 ... allows attackers to execute operating system commands in the context of the site user... leverage the affected 'thin-scc-wrapper' script that's reachable via WebSocket interface to inject and execute arbitrary shell commands"
The payload performs the following sequence of actions - Attempt to patch AMSI and ETW related functionality; Setup persistence using a scheduled task.
The inject mode works by parsing and decrypting shellcode embedded in another PNG file from the archive, and then injecting it into 'vssvc.exe'... A fourth PNG-based payload file... [is] injected into 'ctfmon.exe,' ultimately leading to the execution of Spark RAT.
In the next stage, it decrypts shellcode concealed within a PNG file present in the archive to run a second stager.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An open-source, Go-based remote-access trojan deployed through a multi-stage phishing and DLL side-loading chain. It provides attackers remote control of compromised devices; the campaign uses a vulnerable driver to escalate privileges and disable security products.
An open-source, Go-based, cross-platform remote-access trojan that enables remote control of compromised devices. In this campaign, it is delivered through phishing archives and a multi-stage DLL sideloading and BYOVD chain that disables security tooling, establishes persistence, and injects payloads into Windows processes.
A remote access trojan referenced as one of multiple malware families used by the adversary in attacks targeting sectors in India.
Deployed following exploitation of CVE-2026-1731 as part of an intrusion chain involving web shells, C2, lateral movement, and data theft—consistent with a remote access trojan used to maintain interactive control of compromised environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.