logo

Khmer Shadow Espionage Campaign Targets Cambodian Government

ID: 4322215a-e0bc-5c14-a797-5a42f7cf48bb

STIX ID: report--4322215a-e0bc-5c14-a797-5a42f7cf48bb

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

Author: Do Son

...
...

Acronis Threat Research Unit describes the Khmer Shadow espionage campaign targeting Cambodian defense and public works agencies. Attackers used spear-phishing with a malicious self-extracting archive that leverages DLL sideloading of a VMware-signed binary to run a NIGHTFORGE loader, which decrypts and loads the Havoc Demon implant in memory. The report documents multiple anti-analysis techniques (NTDLL unhooking, Hell’s Gate/syscalls, shellcode injection), scheduled-task persistence, and HTTPS C2 traffic disguised as browser activity; two C2 domains and organization-specific lures are also identified.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.