Site icon VMVirtualMachine.com

Hackers Abuse VMware-Signed Binary to Deploy NIGHTFORGE Loader

Hackers Abuse VMware-Signed Binary to Deploy NIGHTFORGE Loader

Two closely related espionage campaigns targeting Cambodian government organizations that abuse a legitimate VMware-signed binary to sideload a custom loader dubbed NIGHTFORGE, which in turn deploys a Havoc Demon implant in memory.

TRU attributes both operations to a previously unreported cluster it calls Khmer Shadow, based on targeting, lure construction and shared infrastructure; the activity appears focused on defense and military intelligence collection in Southeast Asia.

Both campaigns used meeting- or cooperation-themed self-extracting (SFX) archives delivered likely via spear-phishing.

The archives masqueraded as PDF correspondence and contained a legitimate VMware binary, VMwareNamespaceCmd.exe, alongside a malicious vmtools.dll.

Because VMwareNamespaceCmd.exe statically imports functions from vmtools.dll, Windows loads the attacker-controlled DLL first, enabling the actor to sideload NIGHTFORGE under the context of a VMware-signed process.

One campaign…

Exit mobile version