Sandman APT | China-Based Adversaries Embrace Lua
ID: 352ab6c8-a690-591a-9e29-619c20ae8624
STIX ID: report--352ab6c8-a690-591a-9e29-619c20ae8624
Threat Score
**Executive summary:** SentinelOne/Microsoft/PwC analysis attributes overlap between the Sandman APT and a suspected China-based cluster (STORM-0866/Red Dev 40) by correlating cohabitation of LuaDream and KEYPLUG implants, shared C2 infrastructure and certificates, similar multi-protocol backdoor designs, and overlapping targeting, and provides technical comparisons and IOCs to support continued tracking of Sandman as a distinct but closely related cluster.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
