Sandman APT
MISP
Tipo:
Nation-state
Nation-state
Paese:
CN
CN
Prima attivita:
Unknown
Unknown
Dettagli:
First disclosed in 2023, the Sandman APT is likely associated with suspected China-based threat clusters known for using the KEYPLUG backdoor, specifically STORM-0866/Red Dev 40. Sandman is tracked as a distinct cluster, pending additional conclusive information. A notable characteristic is its use of the LuaDream backdoor. LuaDream is based on the Lua platform, a relatively rare occurrence in the cyberespionage domain, historically associated with APTs considered Western or Western-aligned.
Metadata
| ID: | 556 |
| Created: | 13/01/2026 17:48 |
| Updated: | 08/03/2026 04:00 |