Sandman is a cyberespionage threat cluster first publicly identified in 2023 after intrusions targeting telecommunications providers in the Middle East, Western Europe, and the South Asian subcontinent. The activity is characterized by selective targeting, restrained hands-on-keyboard operations, strategic lateral movement, and efforts to minimize on-host artifacts and detection opportunities. Victimology and tradecraft indicate an intelligence-collection mission focused on telecom environments. Sandman is best known for deploying LuaDream, a large modular backdoor built on LuaJIT. LuaDream is unusual in the espionage landscape because it relies heavily on Lua-based components and supports in-memory staged execution, plugin management, and multiple command-and-control protocols including TCP, HTTPS, WebSocket, and QUIC. The framework includes anti-analysis and evasion features such as thread hiding, sandbox checks, in-memory PE mapping, and other measures intended to reduce visibility to endpoint defenses. Its architecture and active development history indicate a mature malware project rather than a one-off implant. Observed Sandman operations involved theft of administrative credentials, NTLM pass-the-hash, and targeted movement to selected workstations, including systems used by managerial personnel. For persistence and execution, the actor used DLL hijacking involving a malicious library masquerading as a legitimate Windows component and loaded through Windows service processes. Operators were observed waiting for normal service startup or system reboot rather than forcing immediate execution, consistent with a stealth-first approach. Attribution remains cautious but the strongest available reporting links Sandman to the China-linked threat ecosystem. Subsequent analysis associated Sandman with suspected China-based clusters that use the KEYPLUG backdoor, particularly STORM-0866, also known as Red Dev 40. This assessment is based on overlaps in victimology, regional targeting, infrastructure patterns, domain naming conventions, reverse-proxy usage, and the co-occurrence of LuaDream and KEYPLUG within the same victim environments, in some cases on the same endpoints. LuaDream and KEYPLUG are distinct malware families, but they share notable design characteristics, including modular multi-protocol command-and-control, similar execution flow, and comparable data-handling approaches. These overlaps suggest cooperation, shared tooling, or common operational support within a broader China-nexus intrusion landscape. Sandman has also been discussed as a possible contractor or mercenary-style capability because LuaDream initially lacked a clear historical link to a known public threat actor. However, the most current high-confidence assessment places the cluster in close association with China-linked espionage activity. Known aliases include Sandman and sandman_apt.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an APT group associated with the malware file UpdateCheck.dll.
Espionage-motivated activity cluster primarily targeting telecommunications providers, using strategic lateral movement, minimal engagement for stealth, and deploying the LuaDream modular backdoor.
A newly identified threat activity cluster deploying malware that utilizes the LuaJIT platform, an uncommon approach in cyberespionage.
Cyberespionage cluster linked through infrastructure, victimology, and cohabitation to KEYPLUG-using China-based activity; uses the LuaDream modular backdoor and targeted entities in the Middle East and South Asian subcontinent, including telecommunications providers and government entities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.