The other files detected exploiting the new vulnerability followed a similar attack scenario that ended with the installation of Redline Stealer malware. The similarity has two possible explanations: 1. One attacker using different types of malware (the initial file installs SparkRAT malware).
SparkRAT
SparkRAT is an open-source, Go-based cross-platform remote access trojan (RAT) supporting Windows, Linux, and macOS.
Profile source: Mallory opens in a new tabSparkRAT
Family profile
SparkRAT is an open-source, Go-based cross-platform remote access trojan (RAT) supporting Windows, Linux, and macOS. It provides remote command execution, system and host information collection, process and file management, file upload and download, screenshot capture, and payload retrieval. SparkRAT communicates with command-and-control infrastructure using configurable network settings; observed variants have used WebSocket, HTTP, HTTPS, and encrypted C2 communications. It also includes an update mechanism.
SparkRAT has been deployed by multiple unrelated intrusion sets and is not attributable to a single threat actor. Its consistent use was a defining feature of the DragonSpark activity cluster, which was assessed as operated by a Chinese-speaking actor targeting Internet-exposed web and MySQL servers in East Asia. Other observed campaigns have delivered it through trojanized VPN and software installers, Cambodia-themed document lures, malicious shortcut-file exploitation, and exploitation of vulnerable internet-facing remote-management and CI/CD infrastructure. SparkRAT has also been observed as a final in-memory payload following DLL sideloading and process injection. The tool is routinely used to establish interactive remote control, conduct reconnaissance, collect data, and support follow-on intrusion activity.
Capabilities
- Exfiltration
- Post Exploitation
- Reconnaissance
Reported operators
Threat actors
9 named in public reportingThe following public tools were observed on the victims’ network... SparkRAT.
Sandbox family search for family:sparkrat . Returned a per-victim SparkRAT sibling submitted independently to the sandbox. Its ldflags COMMIT differs from the case sample. Confirms the operator uses per-target SparkRAT builds.
...Leslieloader that downloads a backdoor dubbed SparkRAT. The Go variants are compliant with Windows, Linux and OSX. They support file upload and download, system fingerprinting and direct command-line interaction with infected hosts.
"...including CurlBack, SparkRAT, AresRAT, Xeno RAT, AllaKore, and ReverseRAT."
The attacks are characterized by the use of the little known open source SparkRAT and malware that attempts to evade detection through Golang source code interpretation.
...UNK_ColtCentury... likely an attempt to deploy the SparkRAT backdoor.
"CVE-2026-1731 (BeyondTrust) is associated with HAFNIUM and linked to Lumma Stealer, SparkRAT, and VShell malware deployments."
“The primary C2 frameworks observed were Cobalt Strike, VShell, Havoc, Sliver, and SparkRat.”
Exploited software
Vulnerabilities linked to SparkRAT
4 CVEsMITRE ATT&CK