Khmer Shadow Espionage Campaign Targets Cambodian Government
ID: 4322215a-e0bc-5c14-a797-5a42f7cf48bb
STIX ID: report--4322215a-e0bc-5c14-a797-5a42f7cf48bb
Feed Name: securityonline.info
Acronis Threat Research Unit describes the Khmer Shadow espionage campaign targeting Cambodian defense and public works agencies. Attackers used spear-phishing with a malicious self-extracting archive that leverages DLL sideloading of a VMware-signed binary to run a NIGHTFORGE loader, which decrypts and loads the Havoc Demon implant in memory. The report documents multiple anti-analysis techniques (NTDLL unhooking, Hell’s Gate/syscalls, shellcode injection), scheduled-task persistence, and HTTPS C2 traffic disguised as browser activity; two C2 domains and organization-specific lures are also identified.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
