Adversary Intelligence — 2026-06-21

Acronis Uncovers Khmer Shadow Espionage Campaign Targeting Cambodia Defense Intelligence Bureau With Custom NIGHTFORGE Loader

BLUFTargeting of Cambodia's primary defense intelligence collection organ with fabricated Beijing cooperation lures indicates an actor with prior organizational access conducting sustained Southeast Asian military espionage.

Acronis TRU identified two espionage campaigns against Cambodia's Information Collection Bureau, subordinate to the Ministry of National Defense, and the Ministry of Public Works and Transport, attributing both to a previously unreported cluster it calls Khmer Shadow 12. Both operations delivered NIGHTFORGE, a custom loader, via spear-phishing self-extracting archives that sideloaded it through a legitimate VMware-signed binary; the loader performs NTDLL unhooking and Hell's Gate syscall resolution before injecting a Havoc Demon implant into memory 12. The first campaign's lure was a letter addressed to a named ICB officer, purportedly from a Beijing-based "Development and Investment Division" contact, with neither individual traceable in public records 1. Havoc Demon C2 routes to sharingfile.cloud over HTTPS, with origin infrastructure hosted in Kyiv, Ukraine, fronted by Cloudflare; Acronis identified a second domain, linkednewsapi.top, sharing near-identical server characteristics 12.

Analysis
The lure's construction, a named ICB officer and "EOD Administrative team" reference embedded in a fabricated Beijing bilateral coordination request, implies prior reconnaissance rather than generic targeting. Infrastructure and payload reuse across both campaigns without retooling points to either low operational tempo or high confidence in detection immunity. On either reading, the undetected presence extends beyond the discovery window. Acronis TRU holds the only primary analysis; secondary sources introduce factual divergences. Kyiv-hosted C2 origin does not support China attribution, and the cluster remains unlinked to any known group. The Beijing-signed lures may instead represent deliberate false-flag construction, designed to implicate China while an unrelated actor collects against one of its close regional partners.
4 sources
  1. Behind Khmer Shadow: Targeted espionage against Cambodian government entities - Acronis Threat Research Unit
  2. Hackers Abuse VMware-Signed Binary to Deploy NIGHTFORGE Loader - GBHackers
  3. Khmer Shadow Espionage Campaign Targets Cambodian Government - Security Online
  4. Hackers Abuse VMware-Signed Binary to Sideload NIGHTFORGE Loader in Espionage Attacks - CyberSecurityNews

View in full brief →

UNCLASSIFIED // OPEN SOURCE