Summary:
Researchers detected a new threat activity cluster attributed to an unknown actor dubbed "Sandman." Sandman primarily targeted telecommunication providers across the Middle East, Western Europe, and the South Asian subcontinent. Their activities were characterized by strategic lateral movements and minimal engagements, reflecting a deliberate approach to minimize detection risk. The threat actor deployed a sophisticated modular backdoor named "LuaDream" based on the LuaJIT platform, indicating a well-executed and actively developed project. Attribution of Sandman remains challenging, with speculation that it might be a private contractor or mercenary group.[/subscribe_to_unlock_form]
Summary:
Researchers detected a new threat activity cluster attributed to an unknown actor dubbed "Sandman." Sandman primarily targeted telecommunication providers across the Middle East, Western Europe, and the South Asian subcontinent. Their activities were characterized by strategic lateral movements and minimal engagements, reflecting a deliberate approach to minimize detection risk. The threat actor deployed a sophisticated modular backdoor named "LuaDream" based on the LuaJIT platform, indicating a well-executed and actively developed project. Attribution of Sandman remains challenging, with speculation that it might be a private contractor or mercenary group.[emaillocker id="1283"]
LuaDream is a multi-component and multi-protocol backdoor used by Sandman. It has 34 components, both core and support, implemented in LuaJIT bytecode and utilizes the Windows API through C language bindings. LuaDream's core features include exfiltrating system and user information and managing attacker-provided plugins. The backdoor communicates with a C2 server over various protocols, including TCP, HTTPS, WebSocket, and QUIC. It employs anti-analysis measures, such as hiding from debuggers and evading sandbox detection. Sandman used DLL hijacking to execute LuaDream on targeted systems. The staging process is intricate and occurs fully in memory.
Sandman's activities pose a significant threat, particularly to telecommunication providers in multiple regions. While the exact attribution of Sandman remains elusive, the advanced nature of LuaDream suggests a motivated and capable adversary, possibly a private contractor. The continuous development and innovation in their malware arsenal, exemplified by LuaDream, emphasize the importance of information sharing and collaboration within the threat intelligence community.
Threat Profile:

References:
The following reports contain further technical details:
[/emaillocker]