CNChinaconfidence: 50

Sandman APTSandman APT

Also known as: Sandman APT

Origin
CN
Known aliases
1
Target sectors
2
Attribution
State-sponsored

Profile

First disclosed in 2023, the Sandman APT is likely associated with suspected China-based threat clusters known for using the KEYPLUG backdoor, specifically STORM-0866/Red Dev 40. Sandman is tracked as a distinct cluster, pending additional conclusive information. A notable characteristic is its use of the LuaDream backdoor. LuaDream is based on the Lua platform, a relatively rare occurrence in the cyberespionage domain, historically associated with APTs considered Western or Western-aligned.

Aliases· 1

Sandman APT

Target sectors· 2

GovernmentTelecommunications

Known victims· 19

  • Middle East
  • Southeast Asian
  • France
  • Egypt
  • Sudan
  • South Sudan
  • Libya
  • Turkey
  • Saudi Arabia
  • Oman
  • Yemen
  • Sri Lanka

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
APT21
Actor
WARP PANDA
Actor
LIMINAL PANDA
Actor
APT9
Actor
APT31
Actor
APT39
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.