No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

Mysterious ‘Sandman’ APT Targets Telecom Sector With Novel Backdoor

September 22, 2023
in Protection
0
informa



Telecom companies can add one more sophisticated adversary to the already long list of advanced persistent threat (APT) actors they need to protect their data and networks against.

The new threat is “Sandman,” a group of unknown origin that surfaced mirage-like in August and has been deploying a novel backdoor using LuaJIT, a high-performance, just-in-time compiler for the Lua programming language.

Researchers at SentinelOne are tracking the backdoor as “LuaDream” after observing it in attacks on telecommunications companies in the Middle East, Western Europe, and South Asia. Their analysis showed the malware is highly modular with an array of functions for stealing system and user information, enabling future attacks, and managing attacker-provided plugins that extend the malware’s capabilities.

“At this time, there is no reliable sense of attribution,” SentinelOne researcher Aleksandar Milenkoski said in a paper he presented at the company’s LABScon conference this week. “Available data points to a cyber-espionage adversary with a strong focus on targeting telecommunication providers across diverse geographical regions.”

A Popular Target

Telecom companies have long been a popular target for threat actors — especially state-backed ones — because of the opportunities they provide for spying on people and conducting broad cyber espionage. Call-data records, mobile subscriber identity data, and metadata from carrier networks can give attackers a way to track individuals and groups of interest very effectively. Many of the groups conducting these attacks have been based in countries like China, Iran, and Turkey.

More recently, the use of phones for two-factor authentication has given attackers looking to break into online accounts another reason to go after telecom companies. Some of these attacks have involved breaking into carrier networks to conduct SIM-swapping — porting another person’s phone number to an attacker-controlled device — on a mass scale.

Sandman’s main malware, LuaDream, contains 34 distinct components and supports multiple protocols for command-and-control (C2), indicating an operation of considerable scale, Milenkoski noted.

A Curious Choice

Thirteen of the components support core functions such as malware initialization, C2 communications, plugin management, and exfiltration of user and system information. The remaining components perform support functions such as implementing Lua libraries and Windows APIs for LuaDream operations.

One noteworthy aspect of the malware is its use of LuaJIT, Milenkoski noted. LuaJIT is typically something developers use in the context of gaming applications and other specialty applications and use cases. “Highly modular, Lua-utilizing malware is a relatively rare sight, with the Project Sauron cyber-espionage platform being one of the seldom-seen examples,” he said. Its use in APT malware hints at the possibility of a third-party security vendor being involved in the campaign, he also noted.

SentinelOne’s analysis showed that once the threat actor gains access to a target network, one big focus is on laying low and being as unobtrusive as possible. The group initially steals administrative credentials and quietly conducts reconnaissance on the compromised network seeking to break into specifically targeted workstations — especially those assigned to individuals in managerial positions. SentinelOne researchers observed the threat actor maintaining a five-day gap on average between endpoint break-ins to minimize detection. The next step typically involves Sandman actors deploying folders and files for loading and executing LuaDream, Milenkoski said.

LuaDream’s features suggest it is a variant of another malware tool dubbed DreamLand that researchers at Kaspersky observed earlier this year being used in a campaign targeting a Pakistani government agency. Like LuaDream, the malware that Kaspersky discovered also was highly modular as used Lua in conjunction with the JIT compiler to execute code in a difficult-to-detect manner, Milenkoski said. At the time, Kaspersky described the malware as the first instance of an APT actor using Lua since Project Sauron and another older campaign dubbed Animal Farm.

Editorial Team

Editorial Team

Related Posts

The Insta360 Ace Pro 2 Dual Battery Bundle Is 21% Off Right Now
Protection

The Insta360 Ace Pro 2 Dual Battery Bundle Is 21% Off Right Now

May 20, 2026
Why You Should Use Potassium Salt (Even Though It Tastes a Bit Weird)
Protection

Why You Should Use Potassium Salt (Even Though It Tastes a Bit Weird)

May 20, 2026
The Anker Soundcore Liberty 5 Earbuds Are 31% Off Right Now
Protection

The Anker Soundcore Liberty 5 Earbuds Are 31% Off Right Now

May 20, 2026
This Asus Handheld Gaming Console Is $275 Off Right Now
Protection

This Asus Handheld Gaming Console Is $275 Off Right Now

May 20, 2026
Google I/O Live Blog: Android 17, Android XR, Gemini Intelligence, and More
Protection

Google I/O Live Blog: Android 17, Android XR, Gemini Intelligence, and More

May 20, 2026
Windows 11 Will Finally Let Users Move and Resize the Taskbar
Protection

Windows 11 Will Finally Let Users Move and Resize the Taskbar

May 20, 2026
Load More
Next Post
European Stocks Drop as Concerns Over Rates Linger: Markets Wrap

European Stocks Drop as Concerns Over Rates Linger: Markets Wrap

Popular News

  • Why two Wall Street titans have turned bullish on U.S. stocks

    Why two Wall Street titans have turned bullish on U.S. stocks

    0 shares
    Share 0 Tweet 0
  • The Newest Echo Show Is $50 Off Right Now

    0 shares
    Share 0 Tweet 0
  • Gen Z single women are buying homes. They need an estate plan

    0 shares
    Share 0 Tweet 0
  • Allvue and RSM launch AI model to automate capital calls

    0 shares
    Share 0 Tweet 0
  • 10 Best CFD Platforms for Trading in 2023 • Benzinga

    0 shares
    Share 0 Tweet 0

Latest News

Avante Capital closes oversubscribed fourth SBIC fund at $400m

Avante Capital closes fourth SBIC fund at $400m

May 20, 2026
0

Private credit firm Avante Capital Partners has announced the final close of its fourth small business investment company (SBIC) fund...

Bankr

Crypto AI Platform Bankr Locks Down System After Hacker Breaches 14 Crypto Wallets

May 20, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Tech entrepreneur Austen Allred was among the...

Jeff Bezos says bottom half of earners should pay zero in income taxes

Jeff Bezos says bottom half of earners should pay zero in income taxes

May 20, 2026
0

Amazon executive chairman Jeff Bezos on Wednesday called for zero federal income taxes on the bottom half of earners.The top...

Target’s turnaround plan involves upscale baby gear and revamped shopping carts — and it’s starting to work

Target’s turnaround plan involves upscale baby gear and revamped shopping carts — and it’s starting to work

May 20, 2026
0

Target just topped earnings expectations and boosted its outlook.

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.