Sandman, also known as Sandman APT, is a cyberespionage threat cluster identified in 2023 that has primarily targeted telecommunications providers in the Middle East, Western Europe, and the South Asian subcontinent. The cluster deploys LuaDream, a modular LuaJIT-based backdoor built for stealthy in-memory execution, plugin management, host and user-information collection, and encrypted command-and-control communications over multiple protocols. Sandman has used stolen administrative credentials and NTLM pass-the-hash for selective lateral movement to targeted workstations, while limiting on-host activity to reduce detection opportunities. It has deployed LuaDream through DLL side-loading involving Windows services and employs anti-analysis and endpoint-defense evasion measures including thread hiding, sandbox detection, packed code, in-memory PE mapping, and file deletion. Sandman is assessed as likely espionage-motivated and is likely associated with suspected China-based KEYPLUG-using clusters, particularly STORM-0866, also known as Red Dev 40. This assessment is supported by LuaDream and KEYPLUG cohabitation in victim environments, overlapping victimology, infrastructure practices, and malware-design similarities. Sandman’s precise organizational attribution remains unresolved.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
19 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an APT group associated with the malware file UpdateCheck.dll.
Espionage-motivated activity cluster primarily targeting telecommunications providers, using strategic lateral movement, minimal engagement for stealth, and deploying the LuaDream modular backdoor.
A newly identified threat activity cluster deploying malware that utilizes the LuaJIT platform, an uncommon approach in cyberespionage.
Cyberespionage cluster linked through infrastructure, victimology, and cohabitation to KEYPLUG-using China-based activity; uses the LuaDream modular backdoor and targeted entities in the Middle East and South Asian subcontinent, including telecommunications providers and government entities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.