logo

Behind Khmer Shadow: Targeted espionage against Cambodian government entities

ID: b987d4dc-b4d1-5461-93ca-95c18b80995d

STIX ID: report--b987d4dc-b4d1-5461-93ca-95c18b80995d

Feed Name: TRU Security by Acronis

Threat Score
78/100

Date Published: 2026-06-10

Date Updated: 2026-07-24

...
...

**Acronis TRU** identified two espionage-focused campaigns (tracked as **Khmer Shadow**) targeting Cambodian government entities that delivered a custom DLL loader dubbed **NIGHTFORGE** via meeting-themed SFX archives; NIGHTFORGE unhooks NTDLL, resolves syscalls with Hell's Gate, decrypts shellcode on disk, and uses KaynLdr to load a Havoc Demon implant which communicates over HTTPS to sharingfile.cloud and linkednewsapi.top (origin IPs 193.169.240.38 and 104.193.255.99); operators achieved persistence via a scheduled task named "VMwareNamespace", reused infrastructure across targets, and Acronis detects both NIGHTFORGE and Havoc Demon while providing multiple IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.