Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors khmer shadow

Also known as: NIGHTFORGE, tracked as, Wayang Kulit, BibiLeaks, Prabu Bratana, Coroxy, RAT, Glitch SPY, CVE-2026-0257, APT36, Fangneng CDN, Broomstick, CleanUp, composed of multiple stages, CVE-2026-22769, Operation Neusploit, Eastern European region, Operation Dragon Weave, which decrypts, Agenda

Description

Khmer Shadow originated with two espionage campaigns against Cambodian government entities that reportedly leveraged a custom C++ loader called NIGHTFORGE to deliver the Havoc Demon malware framework. The loader embeds sophisticated evasion measures: it sideloads DLLs through legitimate VMware binaries, resolves system calls via Hell's Gate to avoid API hooking, and employs fiber‐based shellcode execution (CreateFiberEx/SwitchToFiber) to bypass user‑mode security tools. In addition, the campaigns repeatedly used self‑extracting archives that contain DLL payloads and LNK attachments that reference fabricated recruiter personas in spear‑phishing emails. Beyond Cambodia, the actor has expanded its footprint: it has abused the PAN‑OS GlobalProtect flaw CVE‑2026‑0257 across multiple regions, carried out adversary‑in‑the‑middle attacks on Microsoft 365 identities, and leveraged compromised cloud resources to host phishing landing pages. This shift illustrates a move from pure exploitation toward identity abuse and supply‑chain compromise. Despite deploying high‑level technical capabilities—including DLL sideloading, triple‑layer encryption (modified RC4 → Base64 → SM4-CBC), sandbox detection on known analyst machine names, and the neutralization of security tooling—Khmer Shadow consistently demonstrates poor operational security. They reuse payloads and command‑and‑control infrastructure across campaigns, enabling easy tracking once a single victim is identified.

Goals & Targeting

Targeted Sectors

Defense
Government
Financial services
Healthcare
Critical infrastructure
Construction
Telecommunications
Media
Energy
Education
Manufacturing
Legal services
Oil gas
Gaming
Mining
Retail
Information technology
Hospitality
Non profit

Targeted Countries / Regions

Cambodia
US
CN
KP
IR
IN
KR
TW
PK
JP
UA
AE
SG
CA
BR
VN
RU
IL
GB

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 5 hours ago

Executive Summary

Khmer Shadow is a China‑state-sponsored threat actor that employs spear‑phishing, credential theft and supply chain techniques to infiltrate government and commercial targets across Southeast Asia and beyond. Their attacks hinge on a custom NIGHTFORGE multi‑stage loader that deploys the Havoc Demon malware via in‑memory execution and sophisticated evasion (fiber shellcode, sandbox checks). While technically advanced, the group frequently reuses infrastructure, rendering their operations both detectable and traceable.

Goals & Targeting

The actor’s overarching objective appears to be espionage with secondary financial motives, focusing on extracting politically or commercially valuable information from government ministries, utilities, and key industry sectors in Southeast Asia. Their target list includes defense, public works, telecommunications, energy, healthcare, finance, and education—industries where compromise can yield strategic insights. Tactically, they employ spear‑phishing with tailored messaging (fake recruiters) to gain initial foothold, then expand privileges via credential theft or adversary‑in‑the‑middle techniques in Microsoft 365. They also exploit infrastructure vulnerabilities (CVE‑2026‑0257) and compromise legitimate cloud assets for C2 or web hosting, aligning with a pattern of blended exploitation—initial phishing followed by supply‑chain or authentication bypass escalation.

Enhanced Description

Key Capabilities

  • Custom NIGHTFORGE/NightForge loader with multi‑stage infection chain
  • In‑memory execution of Havoc Demon malware framework
  • Precision spear‑phishing lures (fake recruiters, device code, Google Ads, procurement scams)
  • Adversary‑in‑the‑middle credential theft on Microsoft 365
  • Phishing via LNK file attachments and device codes
  • Compromise/exploitation of attacker‑controlled infrastructure (domains, cloud resources, compromised sites)
  • Command execution via PowerShell, Python, Bun, Git hooks
  • Exploitation of PAN‑OS GlobalProtect Authentication Bypass CVE‑2026‑0257
  • Triple‑layer encryption/decryption (modified RC4 → Base64 → SM4-CBC) and layered obfuscation
  • Fiber‑based shellcode execution using CreateFiberEx / SwitchToFiber (sandbox/evasion)
  • Sandbox detection against known analyst machine names
  • Neutralization of security tooling before final payload deployment
  • Machine‑specific filename for encrypted payload within legitimate staging directory
  • Self‑extracting archives with DLL sideloading via VMwareNamespaceCmd.exe
  • Persistence via COM‑based scheduled tasks

MITRE ATT&CK Tactics

Initial Access
Credential Access
Command Execution
Defense Evasion
Execution
Reconnaissance

ATT&CK Techniques

T1566
T1583
T1584
T1059
T1566.001
T1055
T1027
T1190
T1195
T1071
T1555
T1556
T1105

Software / Tooling

NIGHTFORGE
Havoc Demon
RUSTCLOAK
KaynLdr
Havoc C2
VMwareNamespaceCmd.exe

Campaigns & Victims

Khmer Shadow’s known campaigns include a Cambodian government espionage operation using NIGHTFORGE and Havoc Demon, followed by an expanded attack vector that exploited the PAN‑OS GlobalProtect CVE‑2026‑0257 to compromise user identities across multiple countries. The actor demonstrates high technical sophistication (DLL sideloading, process injection, fiber shellcode, sandbox detection) but frequently reuses command‑and‑control infrastructure and payloads, making them readily identifiable when a single victim is discovered. Victim types span from defense ministries and public works agencies to telecoms, energy firms and universities, indicating a broad interest in strategic industrial sectors.

IOC Patterns

  • Phishing email attachment with fake recruiter persona
  • Malicious domain used for C2
  • CVE‑2026‑0257 PAN‑OS GlobalProtect authentication bypass exploit
  • Adversary‑in‑the‑middle targeting Microsoft 365
  • Compromised cloud resource used for phishing/malware delivery
  • Machine‑specific encrypted payload filename within staging directory
  • Legitimate VMware‑signed binary used for DLL sideloading
  • Self‑extracting archive containing DLL loader
  • LNK file used in spearphishing delivery
  • Fiber creation API usage (CreateFiberEx/SwitchToFiber) sandbox evasion checks

Recommended Actions

  • Implement robust MFA across all corporate and Microsoft 365 accounts.
  • Enforce email security controls (anti‑phishing filters, attachment sandboxing).
  • Block known malicious domains and monitor for newly registered suspicious domains.
  • Apply latest PAN‑OS updates to mitigate GlobalProtect authentication bypass vulnerability.
  • Continuously monitor attacker‑controlled cloud infrastructure and compromised websites used for C2 or phishing.
  • Detect custom fiber creation APIs such as CreateFiberEx / SwitchToFiber on endpoints.\nDetect and block self‑extracting archives that load DLL payloads.
  • Deploy endpoint behavioral analysis rules to identify sandbox evasion signatures and neutralization of security tools.\nAdd signature rules for triple‑layer decryption patterns (modified RC4 → Base64 → SM4-CBC).
  • Ensure scheduled task creation is monitored and validated for legitimacy.

Suggested Tags

Acronis Threat Research Unit
Khmer Shadow
Nightforge
Havoc Demon
Phishing
Credential Theft
Adversary‑in‑the‑middle
Microsoft 365 abuse
CVE-2026-0257
China State‑Sponsored
Southeast Asia Targeting
Chinese Origin
Espionage
Targeting Government Entities
Spearphishing LNK
Custom Loader
Fiber Injection
Obfuscated Files

Confidence Assessment

The analysis is based on a single publicly released Acronis Threat Research Unit report and ancillary references to CVE‑2026‑0257 exploitation. While evidence of technical capabilities and operational tactics is strong, details regarding the actor’s long‑term strategic goals, precise attribution chain, and full infrastructure mapping remain incomplete. Additional in‑depth reporting or cross‑correlation with other threat research would increase confidence in attributing all observed campaigns to Khmer Shadow.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.acronis.com — Cited by web research for: NIGHTFORGE
  2. www.malwarepatrol.net — Cited by web research for: Coroxy
  3. rootcon.org — Cited by web research for: Operation Dragon Weave
  4. www.itvoice.in — Cited by web research for: Payload
  5. radar.offseq.com — Cited by web research for: Havoc Demon payload
  6. https://acronis.com/threat-research/khmer-shadow — Cited by AI analysis.

Intel Summary

13

Techniques

51

Tools

0

Campaigns

40

IOCs

0

Observed Data

7

Tactics

Tags

APT
Government Targeting
apt
espionage
government
defense
asia
Acronis Threat Research Unit
Khmer Shadow
Nightforge
Havoc Demon
Phishing
Credential Theft
Adversary‑in‑the‑middle
Microsoft 365 abuse
CVE-2026-0257
China State‑Sponsored
Southeast Asia Targeting
Chinese Origin
Espionage
Targeting Government Entities
Spearphishing LNK
Custom Loader
Fiber Injection
Obfuscated Files

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
55%
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.