#SparkRAT
Hackers Using SparkRAT In Wild To Attack Windows, macOS, and Linux Systems
Hackers Using SparkRAT In Wild To Attack Windows, macOS, and Linux Systems
cybersecuritynews.com
January 29, 2025 at 7:59 PM
BeyondTrustの深刻な脆弱性(CVE-2026-1731)を悪用したVShellとSparkRATを確認
#CybersecurityNews
unit42.paloaltonetworks.com/beyondtrust-...
VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)
CVE-2026-1731 is an RCE vulnerability in identity platform BeyondTrust. This flaw allows attackers control of systems without login credentials.
unit42.paloaltonetworks.com
February 21, 2026 at 2:05 PM
This is why you file off those serial numbers! "Pika-who? No, this is a Sparkrat. The stripes are purple and the Thunderat it, uh, converts into is purple with gold stripes. Legally distinct!"
September 17, 2026 at 5:15 PM
Hackers Using SparkRAT In Wild To Attack Windows, macOS, and Linux Systems Cybersecurity research...

https://cybersecuritynews.com/hackers-using-sparkrat-in-wild/

#cyberf="/hashtag/Cyber" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#Cyber #security/hashtag/Security" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#Security #newsef="/hashtag/News" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#News #Cyberattack #News #cyber #attack #cyber #security #news

Event Attributes
Hackers Using SparkRAT In Wild To Attack Windows, macOS, and Linux Systems
cybersecuritynews.com
January 29, 2025 at 1:54 PM
⚠️ RedNovember group exploits unpatched edge devices globally

RedNovember (aka TAG-100/Storm-2077) uses vulnerabilities in firewalls, VPNs, routers, etc., deploying Pantegana, Cobalt Strike & SparkRAT to gain access.

#ransomNews #RedNovember #EdgeDeviceRisk
September 30, 2025 at 3:39 PM
-China says there's 36 major scam gangs in Thailand
-Report on TAG-124 TDS group and the French phone spoofing scene
-Google says it spotted 13mil malicious apps outside Play Store
-Malware reports on NOVA Stealer, FleshStealer, Tria Stealer, SparkRAT, Lynx RaaS, and Coyote banking trojan
January 31, 2025 at 9:28 AM
Have you been wrongly vilified for electric mouse appreciation? If so you may be entitled to Dino Girl compensation. Call 555-SPARKRAT to learn more
June 9, 2026 at 4:48 AM
Our #CVE analysis shows #SparkRAT is gaining traction, targeting Windows, macOS, and Linux. This malware lets attackers perform operations like screenshots & process management, making it highly dangerous.
 
Find out more: www.f5.com/labs/article...
June 10, 2025 at 11:21 PM
Trend Micro researchers have observed instances of threat actors exploiting two disclosed vulnerabilities in TeamCity to deploy different malware types such as the Jasmin ransomware, an XMRig cryptominer variant, and the SparkRAT backdoor.
#Ransomware #CyberAttack
www.trendmicro.com/en_us/resear...
TeamCity Vulnerability Exploits Lead to Jasmin Ransomware, Other Malware Types
CVE-2024-27198 and CVE-2024-27199 are vulnerabilities within the TeamCity On-Premises platform that can allow attackers to gain administrative control over affected systems.
www.trendmicro.com
March 25, 2024 at 5:15 PM
Cats and RATS are all the rage.

State-sponsored hackers from China and Iran are leveraging AI to enhance their cyberattacks. An AI-powered messaging tool is leaking user data from Slack and Discord. A significant cyberattack targeted Smiths Group, a British engineering …

#apple #hackernews #news
Cats and RATS are all the rage.
State-sponsored hackers from China and Iran are leveraging AI to enhance their cyberattacks. An AI-powered messaging tool is leaking user data from Slack and Discord. A significant cyberattack targeted Smiths Group, a British engineering firm. Rockwell Automation disclosed critical vulnerabilities in their products. Researchers discovered new side-channel vulnerabilities affecting Apple CPUs. The Hellcat ransomware gang is focusing on victim humiliation. SparkRAT malware is targeting macOS users and government entities. Flashpoint analyzed the FleshStealer malware. Cybercriminals are exploiting the trust associated with government websites for phishing attacks. Ivan Novikov discussed a US ruling banning certain Chinese and Russian connected car technology imports.
thecyberwire.com
January 30, 2025 at 10:53 PM
詐欺との戦いは長期にわたるものだ。 - Vietnam. vn

最近、カンボジア内務省はSparkRATマルウェアについて警告を発した。攻撃者は政府文書を装い、マルウェアを添付ファイルとして電子メールで送信することで ...
www.vietnam.vn/ja/cuoc-chie...
詐欺との戦いは長期にわたるものだ。
これらの数字は、オンライン詐欺の深刻さを浮き彫りにしている。問題は、詐欺サイトへの取り締まりが強化されるにつれ、犯罪組織がサイバー空間を通じてユーザーや組織を直接攻撃する方向にシフトしていることである。
www.vietnam.vn
September 6, 2026 at 3:38 AM
カンボジアでは、オンライン詐欺の容疑者約4000人が起訴されている。 - Vietnam. vn

同時に、当局は、 政府文書を装った電子メールを通じて拡散されることが多いSparkRATマルウェアを用いたサイバー攻撃の増加について警告を発した。この ...
www.vietnam.vn/ja/campuchia...
カンボジアでは、オンライン詐欺の容疑者約4000人が起訴されている。
(DTTC)-カンボジアは、オンライン詐欺に関連する3億ドル以上の銀行口座を凍結し、約4,000人の容疑者が関与する446件の事件を裁判所に送致した。
www.vietnam.vn
September 3, 2026 at 4:00 AM
Emails disguised as Cambodian government notices and health records deliver Spark RAT.

The chain abuses CVE-2026-36425 in ardrv.sys to gain h…

https://en.hacks.gr/o-efialtis-ton-drivers-pos-oi-chaker-ekmetalleyontai-tin-opswat-gia-na-exoydeterosoyn-to-antivirus-soy/

#SparkRAT #CVE202636425 #BYOVD
September 1, 2026 at 10:13 PM
Spark RAT campaign abuses a vulnerable OPSWAT driver to kill your AV/EDR before it moves in. https://intel.threadlinqs.com/threat/TL-2026-2182 #ThreatIntel #CVE_2026_36425 #SparkRAT #BYOVD
August 28, 2026 at 4:32 PM
August 27, 2026 at 11:36 AM
This week's Bulletproof Hosting Watch is up: https://hrbrmstr.dev/posts/2026-07-20-weekly-bulletproof-report/

One FlokiNET node (AS200651) turned up this week confirmed as both a Tor exit and an active SPARKRAT C2 callback host — same IP, both at once. Whether that's deliberate cover or two […]
Original post on mastodon.social
mastodon.social
July 20, 2026 at 11:31 AM
Further information as to that CVE 2026-1731
This is an eval server command abuse to get in and then jacking DNS queries for commands, sometimes in Base64 to obfuscate, as noted here.
#SparkRAT #BeyondTrust #cyber #CVE #RedTeam #BlueTeam #malware
youtu.be/nYqC0dTX1fg?...
[Trends] [CTT] Deconstructing CVE-2026-1731
YouTube video by nuricaps
youtu.be
February 23, 2026 at 11:46 AM
This sounds a lot like how DragonSpark used SparkRAT for 3 years ago.
February 23, 2026 at 11:33 AM
🚨 RedNovember — a Chinese state-backed group — has been scaling espionage ops across gov, defense, and aerospace.
- Exploiting VPNs, firewalls, OWA
- Using Pantegana, Cobalt Strike, SparkRAT
- Hitting US, EU, Taiwan, Panama

💬 Drop your thoughts & follow @technadu.com for more sharp threat intel.
September 25, 2025 at 7:44 AM