Subhajeet Singha
Subhajeet Singha is a Senior Researcher at Acronis TRU Labs, working around threat intelligence, malware research, and reverse engineering. Subhajeet actively investigates advanced persistent threats (APTs), reverse-engineers complex malware strains, and contributes to research initiatives that improve threat detection & have previously presented research at Virus Bulletin, FIRST Conference, AVAR, ROOTCON.
Session
Acronis Threat Research Unit uncovered a new APT group, tracked as Khmer Shadow, behind two targeted cyber espionage campaigns against high-value Cambodian government institutions. One campaign confirmed spearphishing of named personnel within the Information Collection Bureau (ICB) of Cambodia's Ministry of National Defence, the country's primary military intelligence organ, a rare instance of a threat actor directly targeting a Southeast Asian military intelligence bureau.
Assessed with moderate confidence as Chinese state-sponsored, the actor used precision lures built around a fabricated Chinese development and investment persona, with decoy documents referencing real named contacts inside the targeted bureaus, indicating prior reconnaissance and intelligence-driven targeting consistent with Chinese collection priorities in Southeast Asia.
Both campaigns delivered a custom loader we have named NightForge, which executes a multi-stage infection chain culminating in a Havoc C2 agent. NightForge reflects significant engineering investment: it neutralizes host security tooling before execution and stores an encrypted payload under a machine-specific filename within a legitimately themed staging directory to frustrate detection and cross-victim correlation.