Khmer Shadow is a cyber-espionage cluster associated with targeted intrusions against Cambodian government entities, particularly defense and public works organizations. The activity has been assessed as espionage-motivated and aligned with regional intelligence collection interests in Southeast Asia. Public reporting has not conclusively tied the cluster to a known nation-state actor, and attribution beyond the cluster name remains unconfirmed. One report also tracks the activity under the cluster name Amber Saolao. Khmer Shadow has conducted spear-phishing operations using government-themed lures tailored to Cambodian officials and agencies. The intrusion chain relies on self-extracting archives that abuse DLL sideloading through legitimate VMware-signed executables to launch a custom loader known as NIGHTFORGE. NIGHTFORGE decrypts and executes follow-on payloads in memory, including KaynLdr and a Havoc Demon implant, minimizing on-disk artifacts. The cluster demonstrates mature defense-evasion and post-compromise tradecraft. Reported techniques include DLL sideloading, NTDLL unhooking, direct-syscall execution via Hell's Gate, shellcode injection, and in-memory execution. Persistence has been established through scheduled tasks created via COM-based Task Scheduler APIs. Havoc Demon has been used as the final-stage implant for remote command execution and broader post-exploitation activity, with network traffic disguised to resemble normal browser communications. Known targeting has centered on Cambodian government bodies, including defense and military intelligence-related organizations and public infrastructure ministries. The operational pattern, lure themes, and malware design indicate a focused intelligence-collection mission rather than financially motivated crime or disruptive activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
9 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Targeted Cambodian government agencies using archive-based delivery, DLL sideloading, and named tooling.
Espionage campaign targeting Cambodian defense and public works government entities using spear-phishing, DLL sideloading, a custom NIGHTFORGE loader, and an in-memory Havoc Demon implant for intelligence collection.
Espionage operation targeting Cambodian government institutions, including defense-related bodies and public infrastructure agencies, for regional strategic intelligence collection.
Espionage-focused campaigns targeting Cambodian government entities, particularly defense, military intelligence, and public works, using a custom loader (NIGHTFORGE) to deploy Havoc Demon in memory.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.