Uptime Hamster: 10d 13h 52mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Sandman

Sandman

0 incidentes 0 paises 0 sectores apt CN Ultimo: -
Aliases: APT SANDMAN
Ver en IntelTracker → APTTrail →
Sandman is an espionage-motivated threat actor assessed with high confidence to be of Chinese origin, first documented in August 2023 with activity traced back to early 2022 through malware development timestamps. This group distinguishes itself by deploying LuaDream, a novel modular backdoor utilizing the LuaJIT platform, a rare choice in the advanced persistent threat landscape. Sandman focuses on long-term campaigns against telecommunications and government entities, characterized by strategic lateral movements and minimal engagements designed to evade detection. While initially reported as an unknown entity, later intelligence has strongly linked Sandman to China-based threat clusters like STORM-0866/Red Dev 40, though Sandman is currently tracked as a distinct cluster.

Aliases del actor

APT SANDMAN

Actores similares

apt-sandmanactor · 1apt-45actor · 2apt-c-27actor · 2apt-c-01actor · 2apt-c-12actor · 1apt-18actor · 1apt-1877teamactor · 1apt-27actor · 1apt-30actor · 1apt-38actor · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
Webunknownwww.sentinelone.comAPT SANDMAN indicators and references
Webunknownwww.virustotal.comAPT SANDMAN indicators and references
Repositoriounknowngithub.comAPT SANDMAN indicators and references
Webunknownraw.githubusercontent.comAPT SANDMAN indicators and references
Webunknownwww.sentinelone.comAPT SANDMAN indicators and references
Motivacion