# Khmer Shadow: Amber Saolao cluster targets Cambodian government with NIGHTFORGE loader and Havoc Demon

> Acronis TRU documented two espionage campaigns against Cambodian government entities (the Ministry of National Defence's Information Collection Bureau and the Ministry of Public Works and Transport), tracked collectively as the Amber Saolao cluster (report title "Khmer Shadow"). Both campaigns deliver government-themed lures inside self-extracting archives that sideload a previously undocumented custom loader, NIGHTFORGE, via the legitimate VMware-signed binary VMwareNamespaceCmd.exe.

- **Published:** 2026-08-26T00:00:00Z
- **Last reviewed:** 2026-08-27T14:47:05.123Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2148
- **ID:** TL-2026-2148
- **Severity:** HIGH
- **Category:** APT
- **Status:** ACTIVE
- **Actor:** Amber Saolao
- **Detections:** 9 · **IOCs:** 28 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Acronis Threat Research Unit (TRU) disclosed a pair of closely related, previously untracked espionage operations targeting high-value Cambodian government institutions, publishing its findings on 2026-06-10 under the report title "Behind Khmer Shadow" and tracking the underlying activity as the Amber Saolao cluster. The first operation spear-phished named personnel within the Information Collection Bureau (ICB) of Cambodia's Ministry of National Defence -- the country's primary military intelligence organ -- using a lure disguised as correspondence to a named ICB official ("Contact_Letter_To_Ms_Pech_ICB_Cambodia_On_Collaboration.pdf.exe"). The second targeted the Ministry of Public Works and Transport with a lure referencing bilateral China-Cambodia coordination and site visits ("CN_Contact_Work_Cambodia's_Ministry_of_Public_Works_and_Transport.pdf"). Both lures are delivered as self-extracting (SFX) archives that drop a legitimate, digitally signed VMware utility, VMwareNamespaceCmd.exe, alongside an attacker-controlled DLL named vmtools.dll in the same directory. Because VMwareNamespaceCmd.exe statically imports functions from vmtools.dll, running it forces Windows to load the malicious DLL -- classic DLL side-loading.

vmtools.dll executes NIGHTFORGE, a custom C++ loader that had not previously been documented in public reporting. NIGHTFORGE performs environment/sandbox checks, hides its foreground window, and then evades user-mode security tooling by restoring a clean, on-disk copy of ntdll.dll over the hooked in-memory copy (NTDLL unhooking) before resolving Windows syscall numbers dynamically at runtime using the Hell's Gate technique, letting it issue direct syscalls (NtAllocateVirtualMemory, NtWriteVirtualMemory, NtCreateThreadEx) without transiting monitored API wrappers. It XOR-decrypts an embedded payload and hands off to KaynLdr, a reflective loader that walks the PEB to resolve module bases and hashed APIs and maps the final payload directly into memory. The final payload is an implant built on the open-source Havoc C2 framework's "Demon" agent, injected into a sacrificial gpupdate.exe process (process hollowing). Persistence is established via a COM-created scheduled task named "VMwareNamespace", stored under %LOCALAPPDATA%\VMwareNamespace\, re-triggering roughly every 10 minutes.

Havoc Demon beacons out over HTTPS to sharingfile[.]cloud and a secondary domain, linkednewsapi[.]top, mimicking ordinary Chrome web-browsing traffic (realistic browser headers, rotating decoy paths such as /national, /world, /sport, /download, /regular) and fronted through Cloudflare to conceal the true origin infrastructure, which TRU traced to hosts in Kyiv, Ukraine and Santa Clara, US. TRU assessed with moderate confidence that the shared loader, payload, and C2 infrastructure across both campaigns point to a single cluster, and that the targeting profile (defense and public-works ministries in Cambodia) is consistent with regional intelligence-collection interests in Southeast Asia -- despite deploying comparatively advanced tradecraft (custom loader, direct syscalls, NTDLL unhooking), the operators reused near-identical payloads and infrastructure across both targets with little variation, which TRU noted let researchers pivot from one intrusion to fingerprint the other.

## MITRE ATT&CK

- T1566.001 Spearphishing Attachment
- T1204.002 Malicious File
- T1574.001 DLL
- T1036.005 Match Legitimate Resource Name or Location
- T1027.007 Dynamic API Resolution
- T1140 Deobfuscate/Decode Files or Information
- T1685 Disable or Modify Tools
- T1620 Reflective Code Loading
- T1497 Virtualization/Sandbox Evasion
- T1055.012 Process Hollowing
- T1053.005 Scheduled Task
- T1071.001 Web Protocols
- T1573.002 Asymmetric Cryptography
- T1090.002 External Proxy
- T1106 Native API
- T1574.002 DLL Side-Loading
- T1562.001 Impair Defenses

## Sources

- [Behind Khmer Shadow: Targeted espionage against Cambodian government entities](https://www.acronis.com/en/tru/posts/behind-khmer-shadow-targeted-espionage-against-cambodian-government-entities/)
- [Cambodia-focused cluster uses multi-stage infection chain with localized lures](https://www.acronis.com/en/tru/posts/cambodia-focused-cluster-uses-multi-stage-infection-chain-with-localized-lures/)
- [Hackers Abuse VMware-Signed Binary to Sideload NIGHTFORGE Loader in Espionage Attacks](https://cybersecuritynews.com/hackers-abuse-vmware-signed-binary-to-sideload-nightforge-loader/)
- [Khmer Shadow Targets Cambodian Government with NIGHTFORGE](https://socprime.com/active-threats/khmer-shadow-targets-cambodian-government-entities-in-espionage-campaign/)
- [Hackers Abuse VMware-Signed Binary to Deploy NIGHTFORGE Loader](https://gbhackers.com/hackers-abuse-vmware-signed-binary/)
- [Hackers Abuse VMware-Signed Binary to Sideload NIGHTFORGE Loader](https://cyberpress.org/vmware-binary-sideloads-nightforge/)
- [Acronis Unmasks Espionage Campaigns Targeting Military Intelligence and Public Works in the Cambodian Government Entities Via Sophisticated Malware Framework](https://www.itvoice.in/acronis-unmasks-espionage-campaigns-targeting-military-intelligence-and-public-works-in-the-cambodian-government-entities-via-sophisticated-malware-framework)
- [Daily Cybersecurity Briefing (11 June 2026)](https://www.cybersecbrief.com/news/cybersec/cybersec-2026-06-11)
- [Khmer Shadow: uncovering a targeted cyber espionage campaign against Cambodian military intelligence (VB2026 abstract)](https://www.virusbulletin.com/conference/vb2026/abstracts/khmer-shadow-uncovering-targeted-cyber-espionage-campaign-against-cambodian-military-intelligence/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2148
