Also known as: NIGHTFORGE, tracked as, Wayang Kulit, BibiLeaks, Prabu Bratana, Coroxy, RAT, Glitch SPY, CVE-2026-0257, APT36, Fangneng CDN, Broomstick, CleanUp, composed of multiple stages, CVE-2026-22769, Operation Neusploit, Eastern European region, Operation Dragon Weave, which decrypts, Agenda
Khmer Shadow originated with two espionage campaigns against Cambodian government entities that reportedly leveraged a custom C++ loader called NIGHTFORGE to deliver the Havoc Demon malware framework. The loader embeds sophisticated evasion measures: it sideloads DLLs through legitimate VMware binaries, resolves system calls via Hell's Gate to avoid API hooking, and employs fiber‐based shellcode execution (CreateFiberEx/SwitchToFiber) to bypass user‑mode security tools. In addition, the campaigns repeatedly used self‑extracting archives that contain DLL payloads and LNK attachments that reference fabricated recruiter personas in spear‑phishing emails. Beyond Cambodia, the actor has expanded its footprint: it has abused the PAN‑OS GlobalProtect flaw CVE‑2026‑0257 across multiple regions, carried out adversary‑in‑the‑middle attacks on Microsoft 365 identities, and leveraged compromised cloud resources to host phishing landing pages. This shift illustrates a move from pure exploitation toward identity abuse and supply‑chain compromise. Despite deploying high‑level technical capabilities—including DLL sideloading, triple‑layer encryption (modified RC4 → Base64 → SM4-CBC), sandbox detection on known analyst machine names, and the neutralization of security tooling—Khmer Shadow consistently demonstrates poor operational security. They reuse payloads and command‑and‑control infrastructure across campaigns, enabling easy tracking once a single victim is identified.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Khmer Shadow is a China‑state-sponsored threat actor that employs spear‑phishing, credential theft and supply chain techniques to infiltrate government and commercial targets across Southeast Asia and beyond. Their attacks hinge on a custom NIGHTFORGE multi‑stage loader that deploys the Havoc Demon malware via in‑memory execution and sophisticated evasion (fiber shellcode, sandbox checks). While technically advanced, the group frequently reuses infrastructure, rendering their operations both detectable and traceable.
Goals & Targeting
The actor’s overarching objective appears to be espionage with secondary financial motives, focusing on extracting politically or commercially valuable information from government ministries, utilities, and key industry sectors in Southeast Asia. Their target list includes defense, public works, telecommunications, energy, healthcare, finance, and education—industries where compromise can yield strategic insights. Tactically, they employ spear‑phishing with tailored messaging (fake recruiters) to gain initial foothold, then expand privileges via credential theft or adversary‑in‑the‑middle techniques in Microsoft 365. They also exploit infrastructure vulnerabilities (CVE‑2026‑0257) and compromise legitimate cloud assets for C2 or web hosting, aligning with a pattern of blended exploitation—initial phishing followed by supply‑chain or authentication bypass escalation.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Khmer Shadow’s known campaigns include a Cambodian government espionage operation using NIGHTFORGE and Havoc Demon, followed by an expanded attack vector that exploited the PAN‑OS GlobalProtect CVE‑2026‑0257 to compromise user identities across multiple countries. The actor demonstrates high technical sophistication (DLL sideloading, process injection, fiber shellcode, sandbox detection) but frequently reuses command‑and‑control infrastructure and payloads, making them readily identifiable when a single victim is discovered. Victim types span from defense ministries and public works agencies to telecoms, energy firms and universities, indicating a broad interest in strategic industrial sectors.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on a single publicly released Acronis Threat Research Unit report and ancillary references to CVE‑2026‑0257 exploitation. While evidence of technical capabilities and operational tactics is strong, details regarding the actor’s long‑term strategic goals, precise attribution chain, and full infrastructure mapping remain incomplete. Additional in‑depth reporting or cross‑correlation with other threat research would increase confidence in attributing all observed campaigns to Khmer Shadow.
No campaigns linked yet.
No observed data linked yet.
13
Techniques
51
Tools
0
Campaigns
40
IOCs
0
Observed Data
7
Tactics