Two closely related espionage campaigns targeting Cambodian government organizations that abuse a legitimate VMware-signed binary to sideload a custom loader dubbed NIGHTFORGE, which in turn deploys a Havoc Demon implant in memory.
TRU attributes both operations to a previously unreported cluster it calls Khmer Shadow, based on targeting, lure construction and shared infrastructure; the activity appears focused on defense and military intelligence collection in Southeast Asia.
Both campaigns used meeting- or cooperation-themed self-extracting (SFX) archives delivered likely via spear-phishing.
The archives masqueraded as PDF correspondence and contained a legitimate VMware binary, VMwareNamespaceCmd.exe, alongside a malicious vmtools.dll.
Because VMwareNamespaceCmd.exe statically imports functions from vmtools.dll, Windows loads the attacker-controlled DLL first, enabling the actor to sideload NIGHTFORGE under the context of a VMware-signed process.
One campaign…




