Hacker 'Sandman' attacks telecommunications companies with new LuaDream malware

2023, Sep 23

A previously unknown threat actor named 'Sandman' targets telecommunications service providers in the Middle East, Western Europe and South Asia, using information-stealing malware. module named 'LuaDream'.
This malicious activity was discovered by SentinelLabs in collaboration with QGroup GmbH in August 2023. They named the threat actor and malware after the backdoor's internal name 'DreamLand client'.
Sandman's operating style is to remain hidden to avoid detection while performing lateral movement and maintaining sustained access to breached systems to maximize his cyber espionage activities.
Popular target
The Sandman threat actor targets telecommunications service providers in the Middle East, Western Europe, and South Asia subcontinents.

SentinelOne said the threat actor first gained access to the corporate network using stolen administrative credentials.

After the network was compromised, Sandman was seen using "pass-the-hash" attacks to authenticate with remote servers and services by extracting and reusing stored NTLM hashes stored in memory.

The SentinelLabs report explains that, in one case, all of the workstations targeted by hackers were assigned to administrative staff, suggesting the attacker was interested in privileged or confidential information.
LuaDream malware
SandMan was seen deploying a new modular malware named 'LuaDream' in attacks using DLL hijacking on target systems. The malware gets its name from its use of the LuaJIT just-in-time compiler for the Lua scripting language

The malware is used to collect data and manage plugins that extend its functionality, which are received from the command and control (C2) server and executed locally on the compromised system.

The malware's development appears to be active, with the version string retrieved indicating the release number "12.0.2.5.23.29" and analysts seeing signs of logs and functionality. Testing capability from June 2022.

LuaDream's staging process is based on a complex seven-step in-memory process to avoid detection, initiated by the Windows Fax or Spooler service, which runs a malicious DLL file.
SentinelLabs reports that the timestamps in the DLL files used for command hijacking are very close to those of the attacks, which may indicate they were custom-built for specific intrusions.

Anti-analysis measures during staging include:

Hide LuaDream threads from the debugger.
Close file with an invalid handle.
Detect Wine-based sandbox environments.
In-memory mapping to avoid EDR API hooks and file-based detection.
Encapsulate staging code with XOR-based encryption and compression.
LuaDream consists of 34 components, with 13 core components and 21 support components, using LuaJIT bytecode and Windows API through the ffi library.

The core components handle the main functions of the malware, such as user and system data collection, plugin control, and C2 communication, while the support components handle the technical aspects , like providing Lua libs and Windows API definitions.

After initialization, LuaDream connects to the C2 server (via TCP, HTTPS, WebSocket or QUIC) and sends collected information, including malware versions, IP/MAC addresses, system details executive, etc.

Because attackers deploy specific plugins through LuaDream in each attack, SentinelLabs does not have a complete list of all available plugins.

However, the report notes a module named 'cmd', whose name suggests that it gives attackers the ability to execute commands on the compromised device.

Although some of Sandman's custom malware and parts of its C2 server infrastructure have been exposed, the origin of the threat actor remains unanswered.

Sandman joins a growing list of advanced attackers targeting telecommunications companies for espionage, using unique stealth backdoors that are difficult to detect and stop.

Telecommunications service providers are frequent targets of espionage activities due to the sensitive nature of the data they manage.

Earlier this week, we reported on a new group of operations tracked as 'ShroudedSnooper' using two new backdoors, HTTPSnoop and PipeSnoop, against telecom carriers in the Middle East.

News Related

Sep 20, 2024

VPN RICE LAUNCHES ANDROID TV APP

Dear Customer: We are pleased to announce the launch of the RICE VPN application on the Android TV platform. This is a new step in providing customers with a secure solution and safe Internet access right on the big screen of the TV.Outstanding features of the RICE VPN application on Android
Sep 20, 2024

How to protect your mobile devices, Mac from cyber threats

Macs are famous for their high security, but that doesn't mean they're completely invulnerable. By following best practices and using built-in tools, you can significantly increase the security of your Mac.Here are the steps you need to take to protect your Mac, ensuring your data is safe
Sep 20, 2024

How to identify and remove app monitors on your device

Few types of malware can penetrate as deeply as stalkerware. If someone installs it on your phone, they can not only track your location but also see everything you type into your device. Learn how these apps work and what steps to take if you suspect you're being tracked with one of them.What
Sep 20, 2024

Rice for Firefox VPN App Launched

We are pleased to announce the launch of Rice for Firefox VPN app, a perfect security and privacy tool for Firefox browser users. VPN Rice for Firefox is designed to provide a safe, secure, and unrestricted browsing experience, allowing you to enjoy the internet with peace of mind without worrying
Sep 20, 2024

ANNOUNCEMENT ABOUT RICE VPN SYSTEM MAINTENANCE

Dear Customer,We would like to respectfully announce that Rice VPN system will conduct periodic maintenance to improve service quality and ensure network security.We are very pleased to announce that the Rice VPN system will be upgraded to version 2.0 to bring a better experience and ensure optimal
Sep 20, 2024

Australia Faces a Series of Major Data Breaches

Australia has seen a significant increase in data breaches in 2024, often involving sensitive information such as passwords and financial details. Major companies affected include MediSecure, Ticketmaster, Shell, Telstra and Optus, leaving many individuals at risk of identity theft. Learn how to
Sep 20, 2024

Dollar Data: Be Careful with Cash Incentive Deals

Temu, a globally popular e-commerce platform from China, recently attracted interest and skepticism with its cash incentives for new subscribers. The program seems simple: sign up for an account, refer someone else, and you both get cash. However, everything that is easy comes with a
Sep 20, 2024

Announcement of RICE VPN App Launch on Chrome Web Store

Dear Customer,We're excited to announce the launch of the RICE VPN app on the Chrome Web Store. VPN RICE is an advanced VPN application, designed to provide users with a safe, secure and unlimited web surfing experience. Outstanding Features of VPN RICE:Highly Secure: RICE VPN encrypts all of
Sep 20, 2024

Announcing the Launch of VPNRice App For iOS iPad

We are excited to announce the official launch of the VPNRice app for iOS iPad! This is an important step forward, marking our growth and commitment to providing optimal internet access and security solutions for global users. VPNRice - Safe and Unlimited Internet ExperienceWith the continuous
Sep 20, 2024

Is TikTok safe to use?

TikTok: the social media platform that has captured the hearts and minds of more than a billion users around the world. With engaging short videos and an endless stream of content, it's no wonder the app has become a global phenomenon. But is it really as safe as we think?Turns out, TikTok is
Exclusive Offer
Get your Free 30 days access