SandCat
0 incidentes
0 paises
0 sectores
apt UZ Ultimo: -
Aliases: FinFisher, FinSpy sugiere un enfoque en la vigilancia, recolección de información sensible
SandCat is a state-sponsored advanced persistent threat (APT) group believed to be affiliated with Uzbekistan's State Security Service (SSS), initially observed publicly in December 2018. The group primarily conducts cyber-espionage operations aimed at information theft from targets including government entities, human rights and civil rights groups, and journalists. What uniquely distinguishes SandCat is its historical pattern of poor operational security, which has inadvertently aided researchers in tracking its activities and identifying its toolkit. Despite being publicly identified in 2018, intelligence suggests the group may have been active for approximately ten years prior, evolving its capabilities from purchasing exploits to developing custom malware. SandCat is not an alias for other groups like Fancy Bear or Cozy Bear, nor is it directly synonymous with FruityArmor, though both groups have exploited similar vulnerabilities.