Threat reportAPTTL-2026-2148

Khmer Shadow: Amber Saolao cluster targets Cambodian government with NIGHTFORGE loader and Havoc Demon

highACTIVE

Khmer Shadow (TL-2026-2148), also tracked as Khmer Shadow, is a high-severity advanced persistent threat campaign, first published 2026-08-26 and last reviewed 2026-08-27. It is attributed to Amber Saolao with medium confidence, affects VMware VMwareNamespaceCmd.exe (VMware Tools command-line utility, maps to 17 MITRE ATT&CK techniques (T1027.007, T1036.005, T1053.005), and is covered by 9 detection rules and 28 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
17MITRE ATT&CK
Actors
1Amber Saolao
Detection rules
9SPL · KQL · Sigma
IOCs
28Indicators of compromise

Key facts for TL-2026-2148

Threat ID
TL-2026-2148
Also known as
Khmer Shadow
Severity
HIGH
Status
ACTIVE
Category
APT
First published
Last reviewed
Attribution
Amber Saolao
Attribution confidence
MEDIUM
Motivation
ESPIONAGE
Target sectors
government administration, defense, public works, transport
Target regions
Southeast Asia, cambodia
Detection rules
9
Indicators of compromise
28
Updates
2026-08-27 · revalidated 1× · latest source

Malware and tooling in Khmer Shadow

Malware and tooling: Havoc Demon, NIGHTFORGE, KaynLdr

How Khmer Shadow works

Acronis TRU documented two espionage campaigns against Cambodian government entities (the Ministry of National Defence's Information Collection Bureau and the Ministry of Public Works and Transport), tracked collectively as the Amber Saolao cluster (report title "Khmer Shadow"). Both campaigns deliver government-themed lures inside self-extracting archives that sideload a previously undocumented custom loader, NIGHTFORGE, via the legitimate VMware-signed binary VMwareNamespaceCmd.exe.

Acronis Threat Research Unit (TRU) disclosed a pair of closely related, previously untracked espionage operations targeting high-value Cambodian government institutions, publishing its findings on 2026-06-10 under the report title "Behind Khmer Shadow" and tracking the underlying activity as the Amber Saolao cluster. The first operation spear-phished named personnel within the Information Collection Bureau (ICB) of Cambodia's Ministry of National Defence -- the country's primary military intelligence organ -- using a lure disguised as correspondence to a named ICB official ("Contact_Letter_To_Ms_Pech_ICB_Cambodia_On_Collaboration.pdf.exe"). The second targeted the Ministry of Public Works and Transport with a lure referencing bilateral China-Cambodia coordination and site visits ("CN_Contact_Work_Cambodia's_Ministry_of_Public_Works_and_Transport.pdf"). Both lures are delivered as self-extracting (SFX) archives that drop a legitimate, digitally signed VMware utility, VMwareNamespaceCmd.exe, alongside an attacker-controlled DLL named vmtools.dll in the same directory. Because VMwareNamespaceCmd.exe statically imports functions from vmtools.dll, running it forces Windows to load the malicious DLL -- classic DLL side-loading.

vmtools.dll executes NIGHTFORGE, a custom C++ loader that had not previously been documented in public reporting. NIGHTFORGE performs environment/sandbox checks, hides its foreground window, and then evades user-mode security tooling by restoring a clean, on-disk copy of ntdll.dll over the hooked in-memory copy (NTDLL unhooking) before resolving Windows syscall numbers dynamically at runtime using the Hell's Gate technique, letting it issue direct syscalls (NtAllocateVirtualMemory, NtWriteVirtualMemory, NtCreateThreadEx) without transiting monitored API wrappers. It XOR-decrypts an embedded payload and hands off to KaynLdr, a reflective loader that walks the PEB to resolve module bases and hashed APIs and maps the final payload directly into memory. The final payload is an implant built on the open-source Havoc C2 framework's "Demon" agent, injected into a sacrificial gpupdate.exe process (process hollowing). Persistence is established via a COM-created scheduled task named "VMwareNamespace", stored under %LOCALAPPDATA%\VMwareNamespace\, re-triggering roughly every 10 minutes.

Havoc Demon beacons out over HTTPS to sharingfile[.]cloud and a secondary domain, linkednewsapi[.]top, mimicking ordinary Chrome web-browsing traffic (realistic browser headers, rotating decoy paths such as /national, /world, /sport, /download, /regular) and fronted through Cloudflare to conceal the true origin infrastructure, which TRU traced to hosts in Kyiv, Ukraine and Santa Clara, US. TRU assessed with moderate confidence that the shared loader, payload, and C2 infrastructure across both campaigns point to a single cluster, and that the targeting profile (defense and public-works ministries in Cambodia) is consistent with regional intelligence-collection interests in Southeast Asia -- despite deploying comparatively advanced tradecraft (custom loader, direct syscalls, NTDLL unhooking), the operators reused near-identical payloads and infrastructure across both targets with little variation, which TRU noted let researchers pivot from one intrusion to fingerprint the other.

MITRE ATT&CK techniques used in TL-2026-2148

Defense Evasion

T1027.007 Dynamic API Resolution; T1036.005 Match Legitimate Resource Name or Location; T1055.012 Process Hollowing; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion; T1562.001 Impair Defenses; T1574.001 DLL; T1574.002 DLL Side-Loading; T1620 Reflective Code Loading

Persistence

T1053.005 Scheduled Task

Command and Control

T1071.001 Web Protocols; T1090.002 External Proxy; T1573.002 Asymmetric Cryptography

Execution

T1106 Native API; T1204.002 Malicious File

Initial Access

T1566.001 Spearphishing Attachment

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Khmer Shadow

  • VMware — VMwareNamespaceCmd.exe (VMware Tools command-line utility, digitally signed)
    Vulnerable versions: N/A -- abused via DLL side-loading of a co-located malicious DLL, not a software vulnerability

Remediation for Khmer Shadow

Patches

  • Not applicable -- this activity abuses a legitimate signed VMware utility via DLL side-loading rather than exploiting a software vulnerability; no vendor patch is implicated

Immediate actions

  • Block/alert on C2 domains sharingfile.cloud and linkednewsapi.top and on origin IPs 193.169.240.38 and 104.193.255.99
  • Hunt for VMwareNamespaceCmd.exe executing from non-standard, user-writable, or email-attachment-staging directories alongside a co-located vmtools.dll
  • Hunt for scheduled tasks named 'VMwareNamespace' (COM-created, ~10-minute repeat interval) and for %LOCALAPPDATA%\VMwareNamespace\ artifacts
  • Alert on gpupdate.exe processes with anomalous memory regions or outbound HTTPS connections consistent with process hollowing

Workarounds

  • Security-awareness training for ICB and Ministry of Public Works and Transport personnel on bilateral-coordination and named-official correspondence lure themes observed in this cluster
  • Restrict or monitor use of self-extracting-archive tooling on endpoints that do not require it

Longer-term hardening

  • Deploy EDR/ETW telemetry capable of detecting direct/indirect syscall use (Hell's Gate-style SSN resolution) and NTDLL unhooking rather than relying solely on inline API hooks
  • Application allow-listing to prevent unsigned or co-located DLLs from being side-loaded next to signed binaries such as VMwareNamespaceCmd.exe
  • Restrict execution of self-extracting archives (.exe, .pdf.exe) delivered as email attachments at the mail gateway

Timeline of Khmer Shadow

  • Cloudflare Origin Certificate for sharingfile.cloud goes live, the earliest observed setup of the Havoc Demon C2 infrastructure.
  • A second TLS certificate is issued for linkednewsapi.top, indicating a second Havoc Demon C2 server was being stood up.
  • The sharingfile.cloud TLS certificate first appears in public Certificate Transparency logs, later used by researchers to pivot on and correlate the C2 domain.
  • The sharingfile.cloud TLS certificate is rotated, consistent with ongoing operational maintenance ahead of active campaign use.
  • Virus Bulletin publishes the VB2026 conference abstract previewing Acronis TRU's Havoc C2/NIGHTFORGE infrastructure-hunting findings ahead of the full public writeup.
  • TRU assesses with moderate confidence that the cluster is espionage-motivated and aligned with regional intelligence-collection interests in Southeast Asia, without linking it to a previously known group.
  • Acronis TRU designates the shared-loader, shared-payload, shared-infrastructure activity across both campaigns as a single cluster, tracked as Amber Saolao under the report title "Khmer Shadow".
  • NIGHTFORGE is publicly documented for the first time as a previously undocumented custom C++ loader abusing DLL side-loading of the signed VMwareNamespaceCmd.exe binary.
  • Acronis TRU discloses Campaign 2: spear-phishing of Cambodia's Ministry of Public Works and Transport using a lure referencing bilateral China-Cambodia coordination and site visits.
  • Acronis TRU discloses Campaign 1: spear-phishing of named Information Collection Bureau (ICB) personnel within Cambodia's Ministry of National Defence using a lure disguised as correspondence to a named ICB official.
  • Daily Cybersecurity Briefing aggregates the Khmer Shadow / Amber Saolao disclosure, including the sharingfile.cloud and linkednewsapi.top C2 domains, for the wider SOC community.
  • Independent outlets (Cyber Security News, SOC Prime, GBHackers, CyberPress, IT Voice) publish corroborating technical breakdowns confirming the NIGHTFORGE/Havoc Demon infection chain, VMwareNamespaceCmd.exe/vmtools.dll side-loading, and associated IOCs.

Update history for TL-2026-2148

Sources cited for Khmer Shadow

Detection coverage for TL-2026-2148

As of 2026-08-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2148 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
28 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats