SentinelOne reported that the Sandman APT targeted telecommunications providers with a rare LuaJIT-based malware platform dubbed DreamLand, expanding on earlier reporting that linked the toolkit to an intrusion against a government entity in Pakistan. Researchers described DreamLand as a modular Windows malware family that relies on compiled Lua scripts rather than conventional native implants, an uncommon design choice that complicates reverse engineering and gives operators flexible post-compromise control.
Technical analysis shows the infection chain using libcurl.dll to load UpdateCheck.dll, which then decrypts and decompresses an embedded LuaJIT orchestrator and executes additional compiled scripts stored in updater.ver. The malware includes anti-debugging features and uses Lua FFI to access Windows APIs directly, while configuration data points to HTTPS command-and-control over port 443 via ssl.explorecell.com. Researchers also identified a related loader, Comx64.dll, believed to come from the same developer and built to load shellcode from an encrypted local file, suggesting the toolkit remains under active development and may support future intrusions.

See the actors and campaigns active against you right now.
3 events from the most recent confirmed update back to the earliest known activity.
Additional public analysis documented DreamLand's infection chain using libcurl.dll, UpdateCheck.dll, and updater.ver, along with HTTPS command-and-control configuration pointing to ssl.explorecell.com over port 443. The write-up also described a related sample, Comx64.dll, used to load shellcode from an encrypted local file.
Kaspersky reported discovering a new modular malware strain named DreamLand in March 2023 while it was targeting a government entity in Pakistan. The malware stood out for using LuaJIT and Lua FFI in an APT context.
SentinelOne Labs published research on the Sandman APT, describing a mystery group targeting telecommunications organizations with a LuaJIT-based toolkit. The reference indicates public reporting on the campaign by September 2023.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.