Behind Khmer Shadow: Targeted espionage against Cambodian government entities
ID: b987d4dc-b4d1-5461-93ca-95c18b80995d
STIX ID: report--b987d4dc-b4d1-5461-93ca-95c18b80995d
Feed Name: TRU Security by Acronis
**Acronis TRU** identified two espionage-focused campaigns (tracked as **Khmer Shadow**) targeting Cambodian government entities that delivered a custom DLL loader dubbed **NIGHTFORGE** via meeting-themed SFX archives; NIGHTFORGE unhooks NTDLL, resolves syscalls with Hell's Gate, decrypts shellcode on disk, and uses KaynLdr to load a Havoc Demon implant which communicates over HTTPS to sharingfile.cloud and linkednewsapi.top (origin IPs 193.169.240.38 and 104.193.255.99); operators achieved persistence via a scheduled task named "VMwareNamespace", reused infrastructure across targets, and Acronis detects both NIGHTFORGE and Havoc Demon while providing multiple IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
