Sandman APT is a likely China-linked cyberespionage group targeting government and telecom sectors with the LuaDream backdoor.
Analyst brief
The Sandman APT is a likely China-based cyberespionage group linked to the STORM-0866/Red Dev 40 cluster, though tracked separately pending further attribution. It primarily targets government and telecommunications sectors across the Middle East, Southeast Asia, France, Turkey, Iran, India, Pakistan, and several other nations. Its core TTP involves the use of the LuaDream backdoor, which is built on the rare Lua platform, along with tactical overlaps with groups known for using the KEYPLUG backdoor. Defenders should prioritize monitoring for anomalous Lua script execution, encrypted C2 traffic, and targeted phishing campaigns directed at these specific sectors and regions.
Sandman APT
nation-state
First disclosed in 2023, the Sandman APT is likely associated with suspected China-based threat clusters known for using the KEYPLUG backdoor, specifically STORM-0866/Red Dev 40. Sandman is tracked as a distinct cluster, pending additional conclusive information. A notable characteristic is its use of the LuaDream backdoor. LuaDream is based on the Lua platform, a relatively rare occurrence in the cyberespionage domain, historically associated with APTs considered Western or Western-aligned.
origin (suspected)
🇨🇳China· state-sponsoredattribution confidence: medium (50)
target countries (as stated by the source)
Middle EastSoutheast AsianFranceEgypt
target sectors
GovernmentTelecommunications
source: misp-galaxy
FAQ2
What is the primary backdoor used by the Sandman APT group?+
The core technical characteristic of the Sandman APT group is the use of the LuaDream backdoor, which is based on the Lua platform.
Which sectors does Sandman APT target?+
The group primarily targets government and telecommunications sectors.