Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SentinelLABS has observed a new threat activity cluster by an unknown threat actor we have dubbed Sandman... Sandman has deployed a novel modular backdoor utilizing the LuaJIT platform... We refer to this malware as LuaDream.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The implementation of LuaDream and staging process leverage the LuaJIT platform... This is primarily to make malicious Lua script code difficult to detect.
Next-stage code is typically packed using a combination of XOR-based encryption and compression.
The ualapi.dll file they placed is a malicious DLL masquerading as its legitimate counterpart (a User Access Logging (UAL) component)...
After stealing administrative credentials and conducting reconnaissance, Sandman infiltrated specifically targeted workstations using the pass-the-hash technique over the NTLM authentication protocol.
Some of the implemented anti-analysis measures include... detection of Wine-based sandboxes...
Sandman abused the DLL hijacking technique to execute LuaDream. The ualapi.dll file they placed is a malicious DLL masquerading as its legitimate counterpart... The ualapi.dll library is loaded by the Fax and the Spooler Windows service when started.
Some of the implemented anti-analysis measures include... in-memory mapping of malicious PE images to evade EDR API hooks and file-based detections. | The LuaDream staging chain is designed to evade detection and thwart analysis while deploying the malware directly into memory.
Both backdoors first gather and exfiltrate system and user information in designated functions, with overlaps in gathered information (for example, MAC address, OS version, IP address, computer name, and username).
This information includes the malware version, assigned IP and MAC addresses, OS version, available memory, and the name, PID, and username associated with the process in whose context LuaDream runs.
With the main component initializing LuaDream, the backdoor connects to the configured C2 server and exfiltrates system, user, and malware-related information gathered by BGetSystemMsg . This information includes the malware version, assigned IP and MAC addresses, OS version, available memory...
LuaDream and KEYPLUG are highly modular and multi-protocol in design, both implementing support for the HTTP, TCP, WebSocket, and QUIC protocols for C2 communication.
both implementing support for the HTTP, TCP, WebSocket, and QUIC protocols for C2 communication | The combination of QUIC and WebSocket is a relatively rare backdoor feature and its implementation in both LuaDream and KEYPLUG may be the result of a shared functional requirement by the backdoors’ operators.
PwC tracks STORM-0866/Red Dev 40 as a distinct cluster from the other threat groups using the KEYPLUG malware based on their frequent use of Cloud-based reverse proxy infrastructure, likely as an operational security measure to avoid exposing the true hosting locations. We observed this in the context of Sandman as well, noting a shift from using a directly exposed C2 server IP address (C2 domain: ssl.explorecell[.]com ) to address of a reverse proxy infrastructure (C2 domain: mode.encagil[.]com ).
The backdoor can communicate over the TCP, HTTPS, WebSocket, and QUIC protocols.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A novel modular, multi-component and multi-protocol backdoor built on LuaJIT. It exfiltrates system and user information, supports attacker-provided plugins, can communicate over TCP, HTTPS, WebSocket, and QUIC, and is staged fully in memory with anti-analysis and detection-evasion features.
A maintained modular LuaJIT-based backdoor used in cyberespionage activity. It supports multiple C2 protocols including HTTP, TCP, WebSocket, and QUIC; gathers and exfiltrates system and user information; manages plugins; and uses threaded send/receive C2 handling.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.