Hacker 'Sandman' attacks telecommunications companies with new LuaDream malware

2023, Sep 23

A previously unknown threat actor named 'Sandman' targets telecommunications service providers in the Middle East, Western Europe and South Asia, using information-stealing malware. module named 'LuaDream'.
This malicious activity was discovered by SentinelLabs in collaboration with QGroup GmbH in August 2023. They named the threat actor and malware after the backdoor's internal name 'DreamLand client'.
Sandman's operating style is to remain hidden to avoid detection while performing lateral movement and maintaining sustained access to breached systems to maximize his cyber espionage activities.
Popular target
The Sandman threat actor targets telecommunications service providers in the Middle East, Western Europe, and South Asia subcontinents.

SentinelOne said the threat actor first gained access to the corporate network using stolen administrative credentials.

After the network was compromised, Sandman was seen using "pass-the-hash" attacks to authenticate with remote servers and services by extracting and reusing stored NTLM hashes stored in memory.

The SentinelLabs report explains that, in one case, all of the workstations targeted by hackers were assigned to administrative staff, suggesting the attacker was interested in privileged or confidential information.
LuaDream malware
SandMan was seen deploying a new modular malware named 'LuaDream' in attacks using DLL hijacking on target systems. The malware gets its name from its use of the LuaJIT just-in-time compiler for the Lua scripting language

The malware is used to collect data and manage plugins that extend its functionality, which are received from the command and control (C2) server and executed locally on the compromised system.

The malware's development appears to be active, with the version string retrieved indicating the release number "12.0.2.5.23.29" and analysts seeing signs of logs and functionality. Testing capability from June 2022.

LuaDream's staging process is based on a complex seven-step in-memory process to avoid detection, initiated by the Windows Fax or Spooler service, which runs a malicious DLL file.
SentinelLabs reports that the timestamps in the DLL files used for command hijacking are very close to those of the attacks, which may indicate they were custom-built for specific intrusions.

Anti-analysis measures during staging include:

Hide LuaDream threads from the debugger.
Close file with an invalid handle.
Detect Wine-based sandbox environments.
In-memory mapping to avoid EDR API hooks and file-based detection.
Encapsulate staging code with XOR-based encryption and compression.
LuaDream consists of 34 components, with 13 core components and 21 support components, using LuaJIT bytecode and Windows API through the ffi library.

The core components handle the main functions of the malware, such as user and system data collection, plugin control, and C2 communication, while the support components handle the technical aspects , like providing Lua libs and Windows API definitions.

After initialization, LuaDream connects to the C2 server (via TCP, HTTPS, WebSocket or QUIC) and sends collected information, including malware versions, IP/MAC addresses, system details executive, etc.

Because attackers deploy specific plugins through LuaDream in each attack, SentinelLabs does not have a complete list of all available plugins.

However, the report notes a module named 'cmd', whose name suggests that it gives attackers the ability to execute commands on the compromised device.

Although some of Sandman's custom malware and parts of its C2 server infrastructure have been exposed, the origin of the threat actor remains unanswered.

Sandman joins a growing list of advanced attackers targeting telecommunications companies for espionage, using unique stealth backdoors that are difficult to detect and stop.

Telecommunications service providers are frequent targets of espionage activities due to the sensitive nature of the data they manage.

Earlier this week, we reported on a new group of operations tracked as 'ShroudedSnooper' using two new backdoors, HTTPSnoop and PipeSnoop, against telecom carriers in the Middle East.

News Related

Nov 27, 2024

How to protect yourself from text message scams

Text message scams, commonly known as smishing or SMS scams, are one of the most common methods criminals use to steal important personal and financial information. Recognizing text message scams is important to protect yourself from losing money, having your identity stolen, or having your privacy
Nov 27, 2024

Wi-Fi VPN: How to Keep All Public Wi-Fi Private

The most effective way to protect your data when using public Wi-Fi is to use a VPN (Virtual Private Network). A VPN encrypts your data, which blocks most, if not all, of the ways intruders can steal information via an unsecured Wi-Fi hotspot. We’ve all been tempted by free Wi-Fi —
Nov 27, 2024

What is a network security key? How to find and use a network security key?

These days, we expect hotels to provide us with our Wi-Fi passwords along with our room keys, and asking a friend for the Wi-Fi password is as natural as asking for a glass of water. Yet most of us don’t give it much thought when we log in. Have you ever noticed that it’s called a
Nov 27, 2024

What is the singularity in AI?

The AI ​​singularity is a future scenario where artificial intelligence reaches the point where it can rapidly and continuously improve itself. At that point, humans will have difficulty understanding or controlling the technologies that AI creates, which could lead to machines taking over to
Nov 27, 2024

Steps to Block Ads on Android, iOS, and Other Platforms

Blocking ads can help you have a smoother, faster, and safer online experience. Not only does it clean up your screen, it also improves your device's performance and reduces data usage. Plus, blocking ads reduces the collection of personal data and reduces the risk of encountering malicious
Nov 27, 2024

Is it safe to use Wi-Fi on my computer?

In-flight Wi-Fi poses many of the same security risks as other public Wi-Fi networks. Just like when using Wi-Fi at cafes, airports or hotels, passengers connecting to in-flight Wi-Fi need to be cautious and take protective measures to avoid cyberattacks.In a recent case, in June 2024, an
Nov 27, 2024

How to Block Ads on Android, iOS, and Other Platforms

Why block ads?Optimize device performanceMost online ads contain high-resolution images, graphics, animations, or videos that attract attention, but they also take up a significant amount of your device's processing resources. By blocking ads, you can reduce the load on your CPU, memory, and
Nov 27, 2024

How to Install VPN on Non-Smart TV

So you’ve heard about VPNs (Virtual Private Networks) and the benefits they offer, and now you’re wondering how to set one up on your TV. Whether you have a Smart TV, a regular TV, or are using a streaming device, setting up a VPN can improve your viewing experience in a variety of
Nov 27, 2024

Why do you need a travel VPN router for your family trip?

Of course, security is important. But a portable VPN router also offers convenience, making it easy for everyone in your group to connect to Wi-Fi. In this article, we'll explore why a portable VPN router is a great choice for your family trip.  1. Quickly connect all family devices to
Nov 27, 2024

Firefox vs Google Chrome: Which Browser is Better in 2024?

Choosing a browser is like choosing your first game. While you’re not locked into one browser for life, you can keep using the same one for simplicity’s sake. It’s really easy to default to the popular Google Chrome browser, but Firefox has some serious competition. Firefox is
Exclusive Offer
Get your Free 30 days access