Acronis Threat Research Unit reported that an espionage cluster dubbed Khmer Shadow targeted Cambodian government and public-sector entities, including the Information Collection Bureau under the Ministry of National Defense and the Ministry of Public Works and Transport. The attackers distributed meeting- and government-themed phishing archives containing a legitimate VMware-signed executable, such as VmwareSampling.exe or VMwareNamespaceCmd.exe, alongside a malicious vmtools.dll to trigger DLL sideloading and launch a custom C++ loader called NIGHTFORGE.
NIGHTFORGE decrypted and executed a Havoc Demon payload directly in memory while using NTDLL unhooking, Hell's Gate syscall resolution, and COM-based scheduled-task persistence to evade detection and maintain access. Researchers said the campaigns reused closely related tooling, payloads, and command-and-control infrastructure, including domains such as sharingfile[.]cloud and linkednewsapi[.]top, with traffic routed over ports 443 and 8443 through Cloudflare-fronted infrastructure and backend servers identified in Ukraine and the United States; Acronis linked the activity to a broader cluster it tracks as Amber Saolao and assessed the operations as espionage aligned with regional intelligence collection interests in Southeast Asia.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Cybersecurity News reported Acronis research on the same espionage activity and said Acronis attributed the related campaigns to a threat cluster it tracks as Amber Saolao. The report also highlighted phishing lures, scheduled-task persistence, and command-and-control infrastructure fronted through Cloudflare with backend servers in Ukraine and the United States.
Acronis Threat Research Unit identified two targeted espionage campaigns against Cambodian government entities, including the Information Collection Bureau under the Ministry of National Defense and the Ministry of Public Works and Transport. The campaigns used meeting-themed self-extracting archives to sideload the custom NIGHTFORGE loader via a legitimate VMware binary and a malicious DLL, ultimately executing a Havoc Demon payload in memory.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecybersecuritynews.com
Open sourceacronis.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.