Acronis Uncovers Khmer Shadow Espionage Campaign Targeting Cambodia Defense Intelligence Bureau With Custom NIGHTFORGE Loader
The lure's construction, a named ICB officer and "EOD Administrative team" reference embedded in a fabricated Beijing bilateral coordination request, implies prior reconnaissance rather than generic targeting. Infrastructure and payload reuse across both campaigns without retooling points to either low operational tempo or high confidence in detection immunity. On either reading, the undetected presence extends beyond the discovery window. Acronis TRU holds the only primary analysis; secondary sources introduce factual divergences. Kyiv-hosted C2 origin does not support China attribution, and the cluster remains unlinked to any known group. The Beijing-signed lures may instead represent deliberate false-flag construction, designed to implicate China while an unrelated actor collects against one of its close regional partners.
4 sources
- Behind Khmer Shadow: Targeted espionage against Cambodian government entities -
Acronis Threat Research Unit - Hackers Abuse VMware-Signed Binary to Deploy NIGHTFORGE Loader -
GBHackers - Khmer Shadow Espionage Campaign Targets Cambodian Government -
Security Online - Hackers Abuse VMware-Signed Binary to Sideload NIGHTFORGE Loader in Espionage Attacks -
CyberSecurityNews