Hacker 'Sandman' attacks telecommunications companies with new LuaDream malware

2023, Sep 23

A previously unknown threat actor named 'Sandman' targets telecommunications service providers in the Middle East, Western Europe and South Asia, using information-stealing malware. module named 'LuaDream'.
This malicious activity was discovered by SentinelLabs in collaboration with QGroup GmbH in August 2023. They named the threat actor and malware after the backdoor's internal name 'DreamLand client'.
Sandman's operating style is to remain hidden to avoid detection while performing lateral movement and maintaining sustained access to breached systems to maximize his cyber espionage activities.
Popular target
The Sandman threat actor targets telecommunications service providers in the Middle East, Western Europe, and South Asia subcontinents.

SentinelOne said the threat actor first gained access to the corporate network using stolen administrative credentials.

After the network was compromised, Sandman was seen using "pass-the-hash" attacks to authenticate with remote servers and services by extracting and reusing stored NTLM hashes stored in memory.

The SentinelLabs report explains that, in one case, all of the workstations targeted by hackers were assigned to administrative staff, suggesting the attacker was interested in privileged or confidential information.
LuaDream malware
SandMan was seen deploying a new modular malware named 'LuaDream' in attacks using DLL hijacking on target systems. The malware gets its name from its use of the LuaJIT just-in-time compiler for the Lua scripting language

The malware is used to collect data and manage plugins that extend its functionality, which are received from the command and control (C2) server and executed locally on the compromised system.

The malware's development appears to be active, with the version string retrieved indicating the release number "12.0.2.5.23.29" and analysts seeing signs of logs and functionality. Testing capability from June 2022.

LuaDream's staging process is based on a complex seven-step in-memory process to avoid detection, initiated by the Windows Fax or Spooler service, which runs a malicious DLL file.
SentinelLabs reports that the timestamps in the DLL files used for command hijacking are very close to those of the attacks, which may indicate they were custom-built for specific intrusions.

Anti-analysis measures during staging include:

Hide LuaDream threads from the debugger.
Close file with an invalid handle.
Detect Wine-based sandbox environments.
In-memory mapping to avoid EDR API hooks and file-based detection.
Encapsulate staging code with XOR-based encryption and compression.
LuaDream consists of 34 components, with 13 core components and 21 support components, using LuaJIT bytecode and Windows API through the ffi library.

The core components handle the main functions of the malware, such as user and system data collection, plugin control, and C2 communication, while the support components handle the technical aspects , like providing Lua libs and Windows API definitions.

After initialization, LuaDream connects to the C2 server (via TCP, HTTPS, WebSocket or QUIC) and sends collected information, including malware versions, IP/MAC addresses, system details executive, etc.

Because attackers deploy specific plugins through LuaDream in each attack, SentinelLabs does not have a complete list of all available plugins.

However, the report notes a module named 'cmd', whose name suggests that it gives attackers the ability to execute commands on the compromised device.

Although some of Sandman's custom malware and parts of its C2 server infrastructure have been exposed, the origin of the threat actor remains unanswered.

Sandman joins a growing list of advanced attackers targeting telecommunications companies for espionage, using unique stealth backdoors that are difficult to detect and stop.

Telecommunications service providers are frequent targets of espionage activities due to the sensitive nature of the data they manage.

Earlier this week, we reported on a new group of operations tracked as 'ShroudedSnooper' using two new backdoors, HTTPSnoop and PipeSnoop, against telecom carriers in the Middle East.

News Related

Feb 02, 2026

What is a P2P VPN and how does it work?

Peer-to-peer (P2P) VPNs are an alternative model to traditional VPNs, which rely on centralized servers to route traffic. Instead of concentrating all data at a single central point, P2P VPNs operate on a distributed network where users directly participate as network nodes. Traffic is transmitted
Feb 02, 2026

What is password cracking and how can you prevent it?

Password cracking is a method used by malicious actors to find passwords by systematically guessing or analyzing stolen and encrypted password data. The use of weak passwords or passwords shared across multiple services makes this type of attack far more effective than most users realize.This
Feb 02, 2026

How can I stop receiving spam messages and stay safe?

Spam messages are unwanted content that appears in your inbox, causing a rapid increase in messages and disrupting the tracking of important conversations or notifications. Beyond simply being annoying, many spam messages pose security risks. While some are harmless mass advertisements or marketing
Feb 02, 2026

What is website copying scam and how can you avoid being scammed?

Overview of Clone Phishing Attacks In recent years, online phishing attacks have steadily increased in both scale and sophistication, making it increasingly difficult to distinguish between legitimate and malicious messages. Among the variations of phishing, clone phishing is considered
Feb 02, 2026

Instructions on how to delete your WeChat account

This detailed guide will help you cancel your WeChat account step-by-step in a simple way. We also analyze important issues you need to consider before proceeding, and explain what will happen to your personal data and related services after your account is canceled. Important notes before
Feb 02, 2026

Discord Malware: A Guide to Staying Safe and Cleaning Your Device

1. Overview of Discord and Information Security Risks Discord is a popular online communication platform with a large number of users and a high level of interaction, especially in the fields of gaming, learning and teamwork. However, the open environment, the ability to quickly share files and the
Feb 02, 2026

How do you ping an IP address?

Ping is a basic network diagnostic utility but plays a fundamental role in system administration and network infrastructure operation, operating at the Network layer (Layer 3) of the OSI model and using the ICMP (Internet Control Message Protocol) protocol. The main function of ping is to check the
Feb 02, 2026

Is Your Facebook Account Hacked? How to Detect and Protect Your Account

If you suddenly receive a message from a friend asking if you have created a “new” Facebook account, it is likely that your profile has been cloned. Account cloning occurs when a bad person takes your photo, name, and public information and creates a fake profile to scam you.What is
Feb 02, 2026

Top 10 Video Games That Will Change How You View Privacy

The “hacking” genre – When gamers become hackers Hack is not just about tapping on the keyboard and “successfully accessing” like in Hollywood movies. In the gaming world, hacking has become a genre of its own, where players not only play the role but also live in the
Feb 02, 2026

What is data corruption and how to prevent it?

When Your Files Suddenly Won't OpenYou click on a file, but it doesn't respond. Or worse, an important document turns into a mess of characters. That's a sign of data corruption — an annoying and potentially devastating occurrence.Data corruption happens unexpectedly, costing you
Exclusive Offer
Get your Free 30 days access