Threat reportAPTTL-2026-2148
Khmer Shadow: Amber Saolao cluster targets Cambodian government with NIGHTFORGE loader and Havoc Demon
Khmer Shadow (TL-2026-2148), also tracked as Khmer Shadow, is a high-severity advanced persistent threat campaign, first published 2026-08-26 and last reviewed 2026-08-27. It is attributed to Amber Saolao with medium confidence, affects VMware VMwareNamespaceCmd.exe (VMware Tools command-line utility, maps to 17 MITRE ATT&CK techniques (T1027.007, T1036.005, T1053.005), and is covered by 9 detection rules and 28 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 17MITRE ATT&CK
- Actors
- 1Amber Saolao
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 28Indicators of compromise
Key facts for TL-2026-2148
- Threat ID
- TL-2026-2148
- Also known as
- Khmer Shadow
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- Last reviewed
- Attribution
- Amber Saolao
- Attribution confidence
- MEDIUM
- Motivation
- ESPIONAGE
- Target sectors
- government administration, defense, public works, transport
- Target regions
- Southeast Asia, cambodia
- Detection rules
- 9
- Indicators of compromise
- 28
- Updates
- 2026-08-27 · revalidated 1× · latest source
Malware and tooling in Khmer Shadow
Malware and tooling: Havoc Demon, NIGHTFORGE, KaynLdr
How Khmer Shadow works
Acronis TRU documented two espionage campaigns against Cambodian government entities (the Ministry of National Defence's Information Collection Bureau and the Ministry of Public Works and Transport), tracked collectively as the Amber Saolao cluster (report title "Khmer Shadow"). Both campaigns deliver government-themed lures inside self-extracting archives that sideload a previously undocumented custom loader, NIGHTFORGE, via the legitimate VMware-signed binary VMwareNamespaceCmd.exe.
Acronis Threat Research Unit (TRU) disclosed a pair of closely related, previously untracked espionage operations targeting high-value Cambodian government institutions, publishing its findings on 2026-06-10 under the report title "Behind Khmer Shadow" and tracking the underlying activity as the Amber Saolao cluster. The first operation spear-phished named personnel within the Information Collection Bureau (ICB) of Cambodia's Ministry of National Defence -- the country's primary military intelligence organ -- using a lure disguised as correspondence to a named ICB official ("Contact_Letter_To_Ms_Pech_ICB_Cambodia_On_Collaboration.pdf.exe"). The second targeted the Ministry of Public Works and Transport with a lure referencing bilateral China-Cambodia coordination and site visits ("CN_Contact_Work_Cambodia's_Ministry_of_Public_Works_and_Transport.pdf"). Both lures are delivered as self-extracting (SFX) archives that drop a legitimate, digitally signed VMware utility, VMwareNamespaceCmd.exe, alongside an attacker-controlled DLL named vmtools.dll in the same directory. Because VMwareNamespaceCmd.exe statically imports functions from vmtools.dll, running it forces Windows to load the malicious DLL -- classic DLL side-loading.
vmtools.dll executes NIGHTFORGE, a custom C++ loader that had not previously been documented in public reporting. NIGHTFORGE performs environment/sandbox checks, hides its foreground window, and then evades user-mode security tooling by restoring a clean, on-disk copy of ntdll.dll over the hooked in-memory copy (NTDLL unhooking) before resolving Windows syscall numbers dynamically at runtime using the Hell's Gate technique, letting it issue direct syscalls (NtAllocateVirtualMemory, NtWriteVirtualMemory, NtCreateThreadEx) without transiting monitored API wrappers. It XOR-decrypts an embedded payload and hands off to KaynLdr, a reflective loader that walks the PEB to resolve module bases and hashed APIs and maps the final payload directly into memory. The final payload is an implant built on the open-source Havoc C2 framework's "Demon" agent, injected into a sacrificial gpupdate.exe process (process hollowing). Persistence is established via a COM-created scheduled task named "VMwareNamespace", stored under %LOCALAPPDATA%\VMwareNamespace\, re-triggering roughly every 10 minutes.
Havoc Demon beacons out over HTTPS to sharingfile[.]cloud and a secondary domain, linkednewsapi[.]top, mimicking ordinary Chrome web-browsing traffic (realistic browser headers, rotating decoy paths such as /national, /world, /sport, /download, /regular) and fronted through Cloudflare to conceal the true origin infrastructure, which TRU traced to hosts in Kyiv, Ukraine and Santa Clara, US. TRU assessed with moderate confidence that the shared loader, payload, and C2 infrastructure across both campaigns point to a single cluster, and that the targeting profile (defense and public-works ministries in Cambodia) is consistent with regional intelligence-collection interests in Southeast Asia -- despite deploying comparatively advanced tradecraft (custom loader, direct syscalls, NTDLL unhooking), the operators reused near-identical payloads and infrastructure across both targets with little variation, which TRU noted let researchers pivot from one intrusion to fingerprint the other.
MITRE ATT&CK techniques used in TL-2026-2148
Defense Evasion
T1027.007 Dynamic API Resolution; T1036.005 Match Legitimate Resource Name or Location; T1055.012 Process Hollowing; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion; T1562.001 Impair Defenses; T1574.001 DLL; T1574.002 DLL Side-Loading; T1620 Reflective Code Loading
Persistence
Command and Control
T1071.001 Web Protocols; T1090.002 External Proxy; T1573.002 Asymmetric Cryptography
Execution
T1106 Native API; T1204.002 Malicious File
Initial Access
T1566.001 Spearphishing Attachment
defense-impairment
Affected products and versions in Khmer Shadow
- VMware — VMwareNamespaceCmd.exe (VMware Tools command-line utility, digitally signed)
Vulnerable versions: N/A -- abused via DLL side-loading of a co-located malicious DLL, not a software vulnerability
Remediation for Khmer Shadow
Patches
- Not applicable -- this activity abuses a legitimate signed VMware utility via DLL side-loading rather than exploiting a software vulnerability; no vendor patch is implicated
Immediate actions
- Block/alert on C2 domains sharingfile.cloud and linkednewsapi.top and on origin IPs 193.169.240.38 and 104.193.255.99
- Hunt for VMwareNamespaceCmd.exe executing from non-standard, user-writable, or email-attachment-staging directories alongside a co-located vmtools.dll
- Hunt for scheduled tasks named 'VMwareNamespace' (COM-created, ~10-minute repeat interval) and for %LOCALAPPDATA%\VMwareNamespace\ artifacts
- Alert on gpupdate.exe processes with anomalous memory regions or outbound HTTPS connections consistent with process hollowing
Workarounds
- Security-awareness training for ICB and Ministry of Public Works and Transport personnel on bilateral-coordination and named-official correspondence lure themes observed in this cluster
- Restrict or monitor use of self-extracting-archive tooling on endpoints that do not require it
Longer-term hardening
- Deploy EDR/ETW telemetry capable of detecting direct/indirect syscall use (Hell's Gate-style SSN resolution) and NTDLL unhooking rather than relying solely on inline API hooks
- Application allow-listing to prevent unsigned or co-located DLLs from being side-loaded next to signed binaries such as VMwareNamespaceCmd.exe
- Restrict execution of self-extracting archives (.exe, .pdf.exe) delivered as email attachments at the mail gateway
Timeline of Khmer Shadow
- Cloudflare Origin Certificate for sharingfile.cloud goes live, the earliest observed setup of the Havoc Demon C2 infrastructure.
- A second TLS certificate is issued for linkednewsapi.top, indicating a second Havoc Demon C2 server was being stood up.
- The sharingfile.cloud TLS certificate first appears in public Certificate Transparency logs, later used by researchers to pivot on and correlate the C2 domain.
- The sharingfile.cloud TLS certificate is rotated, consistent with ongoing operational maintenance ahead of active campaign use.
- Virus Bulletin publishes the VB2026 conference abstract previewing Acronis TRU's Havoc C2/NIGHTFORGE infrastructure-hunting findings ahead of the full public writeup.
- TRU assesses with moderate confidence that the cluster is espionage-motivated and aligned with regional intelligence-collection interests in Southeast Asia, without linking it to a previously known group.
- Acronis TRU designates the shared-loader, shared-payload, shared-infrastructure activity across both campaigns as a single cluster, tracked as Amber Saolao under the report title "Khmer Shadow".
- NIGHTFORGE is publicly documented for the first time as a previously undocumented custom C++ loader abusing DLL side-loading of the signed VMwareNamespaceCmd.exe binary.
- Acronis TRU discloses Campaign 2: spear-phishing of Cambodia's Ministry of Public Works and Transport using a lure referencing bilateral China-Cambodia coordination and site visits.
- Acronis TRU discloses Campaign 1: spear-phishing of named Information Collection Bureau (ICB) personnel within Cambodia's Ministry of National Defence using a lure disguised as correspondence to a named ICB official.
- Daily Cybersecurity Briefing aggregates the Khmer Shadow / Amber Saolao disclosure, including the sharingfile.cloud and linkednewsapi.top C2 domains, for the wider SOC community.
- Independent outlets (Cyber Security News, SOC Prime, GBHackers, CyberPress, IT Voice) publish corroborating technical breakdowns confirming the NIGHTFORGE/Havoc Demon infection chain, VMwareNamespaceCmd.exe/vmtools.dll side-loading, and associated IOCs.
Update history for TL-2026-2148
- 2026-08-27 — Khmer Shadow: New APT Group Deploys NIGHTFORGE Loader Against Cambodian Government in Espionage Campaign: What changed No severity/exploitability/status escalation. Newer reporting adds a pre-disclosure C2 infrastructure timeline (certificate issuance/rotation back to 2025-12-01) and extends MITRE coverage. New indicators (10) 10 new IOCs: 3 ad
Sources cited for Khmer Shadow
- Behind Khmer Shadow: Targeted espionage against Cambodian government entities
- Cambodia-focused cluster uses multi-stage infection chain with localized lures
- Hackers Abuse VMware-Signed Binary to Sideload NIGHTFORGE Loader in Espionage Attacks
- Khmer Shadow Targets Cambodian Government with NIGHTFORGE
- Hackers Abuse VMware-Signed Binary to Deploy NIGHTFORGE Loader
- Hackers Abuse VMware-Signed Binary to Sideload NIGHTFORGE Loader
- Acronis Unmasks Espionage Campaigns Targeting Military Intelligence and Public Works in the Cambodian Government Entities Via Sophisticated Malware Framework
- Daily Cybersecurity Briefing (11 June 2026)
- Khmer Shadow: uncovering a targeted cyber espionage campaign against Cambodian military intelligence (VB2026 abstract)
Detection coverage for TL-2026-2148
As of 2026-08-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2148 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.