Summary:
The researchers discuss the Sandman APT cluster and its association with suspected China-based threat clusters, particularly the KEYPLUG backdoor used by STORM-0866/Red Dev 40. The researchers present attribution-relevant information, emphasizing links between Sandman and the threat actor. The focus is on infrastructure control, victimology overlaps, and shared practices, such as hosting provider selections and domain naming conventions. This also notes the adoption of the Lua development paradigm in the cyberespionage domain, historically associated with Western actors but now utilized by a broader range of adversaries, including those with ties to China.[/subscribe_to_unlock_form]
Summary:
The researchers discuss the Sandman APT cluster and its association with suspected China-based threat clusters, particularly the KEYPLUG backdoor used by STORM-0866/Red Dev 40. The researchers present attribution-relevant information, emphasizing links between Sandman and the threat actor. The focus is on infrastructure control, victimology overlaps, and shared practices, such as hosting provider selections and domain naming conventions. This also notes the adoption of the Lua development paradigm in the cyberespionage domain, historically associated with Western actors but now utilized by a broader range of adversaries, including those with ties to China.[emaillocker id="1283"]
The technical analysis encompasses multifaceted aspects, dissecting infrastructure overlaps between Sandman and STORM-0866/Red Dev 40. It discusses SSL certificates, IP addresses, and domain resolutions, highlighting the complex web of shared infrastructure control and management practices. The report also dissects the LuaDream and KEYPLUG malware strains, pointing out indicators of shared development practices and design overlaps. The modular and multi-protocol nature of these malware strains, supporting HTTP, TCP, WebSocket, and QUIC protocols, is examined in detail. The execution flow, C2 data management, and code comments in Chinese within the LuaDream malware suggest potential Chinese origin.
The analysis emphasizes the strong overlaps in operational infrastructure, targeting, and Tactics, Techniques, and Procedures (TTPs) linking the Sandman APT to China-based adversaries employing the KEYPLUG backdoor, particularly STORM-0866/Red Dev 40. The collaboration and coordination observed among Chinese threat actors, as illustrated by shared practices and infrastructure, pose challenges for accurate threat clustering. The report underscores the need for continuous collaboration and information sharing within the threat intelligence research community to effectively navigate the evolving Chinese threat landscape. The adoption of the Lua development paradigm by a broader set of cyberespionage threat actors is highlighted as a noteworthy trend indicative of ongoing innovation and cooperation within the threat landscape.
Threat Profile:

References:
The following reports contain further technical details:
https://thehackernews.com/2023/12/researchers-unmask-sandman-apts-hidden.html
[/emaillocker]