Dec. 11, 2023, 2:01 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

By Aleksandar Milenkoski, Bendik Hagen (PwC), and Microsoft Threat Intelligence


Executive Summary



  • The Sandman APT is likely associated with suspected China-based threat clusters known to use the KEYPLUG backdoor, in particular a cluster jointly presented by PwC and Microsoft at Labscon 2023 – STORM-0866/Red Dev 40.

  • The Sandman’s Lua-based malware LuaDream and the KEYPLUG backdoor were observed co-existing in the same victim environments.

  • Sandman and STORM-0866/Red Dev 40 share infrastructure control and management practices, including hosting provider selections, and domain …

adversaries apt backdoor china cluster clusters dev executive intelligence keyplug labscon lua malware malware analysis microsoft microsoft threat intelligence pwc sandman sandman apt storm threat threat clusters threat intelligence

Senior Security Engineer - Detection and Response

@ Fastly, Inc. | US (Remote)

Application Security Engineer

@ Solidigm | Zapopan, Mexico

Defensive Cyber Operations Engineer-Mid

@ ISYS Technologies | Aurora, CO, United States

Manager, Information Security GRC

@ OneTrust | Atlanta, Georgia

Senior Information Security Analyst | IAM

@ EBANX | Curitiba or São Paulo

Senior Information Security Engineer, Cloud Vulnerability Research

@ Google | New York City, USA; New York, USA