Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Khmer Shadow targeted Cambodian government agencies using SFX archives, DLL sideloading, NIGHTFORGE, and Havoc Demon.
Threat actors have been abusing a legitimate, digitally signed VMware binary to slip a custom malicious loader called NIGHTFORGE onto victim systems.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
Recipients see a file like “Contact_Letter_To_Ms_Pech_ICB_Cambodia_On_Collaboration.pdf.exe,” which is actually a self-extracting archive hiding malware.
The NIGHTFORGE loader includes multiple anti-analysis features. It unhooks NTDLL to bypass malware defenses, uses the Hell’s Gate technique to call Windows APIs covertly via syscalls, and injects shellcode directly into memory.
The malicious vmtools.dll acts as the NIGHTFORGE loader, which decrypts and launches a Havoc Demon implant directly in memory leaving no traces on disk.
The code decodes the encoded shellcode blob present on disk using a simple XOR method. It reads the first 8 bytes of the encrypted file and XORs them against a hardcoded magic value... then decrypts the remaining contents using a rolling 8-byte XOR.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used by Khmer Shadow against Cambodian government agencies.
A custom loader used in the Khmer Shadow espionage campaign. It is delivered via spear-phishing, abuses DLL sideloading with a legitimate VMware-signed binary, decrypts and launches a Havoc Demon implant directly in memory, unhooks NTDLL, uses Hell’s Gate syscalls for evasion, injects shellcode into memory, and establishes persistence via a scheduled task named "VMwareNamespace."
Custom malicious loader delivered via DLL sideloading using a legitimate VMware-signed binary. It performs NT DLL unhooking, uses HellsGate to resolve system calls at runtime, decrypts and injects a Havoc Demon payload into memory, and establishes persistence via a scheduled task named VmwareSampling.
A custom DLL-based C++ loader delivered via DLL sideloading using VMwareNamespaceCmd.exe and vmtools.dll. It establishes persistence via a scheduled task, unhooks NTDLL, resolves syscalls with Hell's Gate, decrypts an on-disk shellcode blob, and injects/executes the next stage in memory.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.