Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Sandman APT

Description

First disclosed in 2023, the Sandman APT is likely associated with suspected China-based threat clusters known for using the KEYPLUG backdoor, specifically STORM-0866/Red Dev 40. Sandman is tracked as a distinct cluster, pending additional conclusive information. A notable characteristic is its use of the LuaDream backdoor. LuaDream is based on the Lua platform, a relatively rare occurrence in the cyberespionage domain, historically associated with APTs considered Western or Western-aligned.

Goals & Targeting

Targeted Sectors

Government
Telecommunications

AI Analysis

· 2 weeks ago

Executive Summary

Sandman APT is a suspected nation-state cyber espionage group likely originating from China. Known for using the KEYPLUG backdoor (STORM-0866/Red Dev 40) and LuaDream malware based on the Lua platform, Sandman targets government and telecommunications sectors with sophisticated campaigns.

Goals & Targeting

Sandman APT appears to target sectors rich in sensitive data for espionage purposes. Government institutions and telecom companies are prime targets due to their access to state secrets and critical communications infrastructure. The group's suspected Chinese origin aligns it with broader nation-state objectives typically aimed at national security, economic gain, or political influence.

Enhanced Description

Sandman APT gained attention in 2023 as a potential nation-state actor linked to Chinese-based threat clusters. The group is distinguished by its use of the KEYPLUG backdoor variant STORM-0866/Red Dev 40, and the LuaDream backdoor, which operates on the relatively uncommon Lua platform. This rarity marks Sandman as unique in the cyberespionage landscape. The group's targeting suggests a focus on intelligence gathering from government and telecommunications infrastructure, likely for political or economic advantage associated with Chinese interests.

Key Capabilities

  • Nation-state level cyberespionage operations
  • Deployment of custom malware like KEYPLUG and LuaDream backdoors
  • Spear-phishing campaigns leveraging malicious attachments
  • Persistent and stealthy access to targeted networks

MITRE ATT&CK Tactics

Espionage
Adversary in the Development Sector

ATT&CK Techniques

T1064.002
T1565.002
T1078

Software / Tooling

KEYPLUG (STORM-0866/Red Dev 40)
LuaDream
Custom Lua-based malware

Campaigns & Victims

Sandman APT's campaigns are characterized by subtle and targeted operations, focusing on long-term access through backdoors like KEYPLUG and LuaDream. The group likely operates with significant resources and sophistication typical of state-sponsored actors. No specific campaigns have been widely reported as of 2023, but its emergence suggests ongoing activity in the cyber espionage landscape.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • Lua-based malware components in network traffic
  • Network communication anomalies indicative of C2 channels

Recommended Actions

  • Implement robust endpoint detection and response (EDR) solutions to identify Lua-based threats.
  • Monitor network traffic for signs of backdoor activity and unknown command-and-control communications.
  • Conduct regular phishing simulations to enhance employee awareness of spear-phishing tactics.
  • Secure critical infrastructure, especially in the telecom sector, against advanced persistent threat actors.

Suggested Tags

APT
espionage
nation-state
KEYPLUG
LuaDream
telecommunications

Confidence Assessment

Confidence in Sandman APT's nation-state affiliation is high based on its suspected Chinese origins and use of sophisticated tools. However, the full scope of its operations and long-term goals remain somewhat unclear due to limited publicly available information beyond its initial disclosure.

Threat Intelligence Report

No report generated yet.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Backdoor / C2
espionage
nation-state
KEYPLUG
LuaDream
telecommunications

Details

Type
Nation-State
Country of Origin
C
Confidence
50%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.