Acronis Unmasks Espionage Campaigns Targeting Military Intelligence and Public Works In The Cambodian Government Entities Via Sophisticated Malware Framework

Acronis Threat Research Unit (TRU) has uncovered two targeted espionage campaigns aimed at Cambodian Government entities in the defense and public works sectors, revealing the growing sophistication of cyber operations targeting public institutions across Southeast Asia. Detailed in Acronis’ latest threat research report, the campaigns leveraged a previously undocumented custom loader dubbed NIGHTFORGE to deploy the Havoc Demon malware framework while evading traditional security controls.

According to the report, the threat cluster, tracked by Acronis as Khmer Shadow, used government themed lure documents delivered through self extracting archives masquerading as legitimate files. The attacks employed DLL sideloading techniques using trusted VMware signed binaries to execute NIGHTFORGE, which subsequently decrypted and launched Havoc Demon directly in memory. Researchers observed that both campaigns targeted Cambodian government organisations, including entities linked to defense and military intelligence operations.

TRU researchers identified several advanced defense evasion techniques within the malware chain, including NTDLL unhooking, Hell’s Gate syscall resolution, in-memory payload execution and COM based persistence mechanisms. Despite demonstrating a moderate level of technical sophistication, the operators repeatedly reused infrastructure, payloads and operational methods across campaigns, enabling researchers to identify additional malicious assets and infrastructure linked to the activity cluster.

The report further highlights how threat actors are increasingly blending advanced malware capabilities with trusted software components and legitimate system processes to evade detection and maintain long term access within targeted environments. Acronis assesses with moderate confidence that the activity is espionage motivated and aligned with regional intelligence collection interests in Southeast Asia.

To defend against similar threats, Acronis recommends that organisations strengthen monitoring of trusted applications and software dependencies, implement robust endpoint detection capabilities, continuously assess suspicious persistence mechanisms and maintain proactive threat hunting practices to identify malicious activity before it escalates.

For more information and additional insights, visit:
https://www.acronis.com/en/tru/posts/behind-khmer-shadow-targeted-espionage-against-cambodian-government-entities

Disclaimer: The above press release has been provided by Consocia Advisory. CXO Digital Pulse holds no responsibility for its content in any manner. Reproduction or Copying in part or whole is not permitted unless approved by author.

- Advertisement -

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles

error: Content is protected !!

Share your details to download the CISO Handbook 2026

Share your details to download the report 2026

Share your details to download the Cybersecurity Report 2025

Share your details to download the CISO Handbook 2025

Sign Up for CXO Digital Pulse Newsletters

Share your details to download the Research Report

Share your details to download the Coffee Table Book

Share your details to download the Vision 2023 Research Report

Download 8 Key Insights for Manufacturing for 2023 Report

Sign Up for CISO Handbook 2023

Download India’s Cybersecurity Outlook 2023 Report

Unlock Exclusive Insights: Access the article

Download CIO VISION 2024 Report

Share your details to download the report

Share your details to download the CISO Handbook 2024

Fill your details to Watch