SandCat is an Uzbekistan-based advanced persistent threat actor linked to Uzbekistan’s State Security Service (SSS), formerly the National Security Service. Its activity is associated with state-linked cyberespionage. SandCat was identified following the discovery of CHAINSHOT malware deployed through a zero-day exploit on a victim system in the Middle East in October 2018. Investigation subsequently uncovered three additional zero-day exploits used by the group. Its exploit usage overlapped with that of separate state-linked actors associated with Saudi Arabia and the United Arab Emirates; this overlap does not establish that those actors are part of SandCat. SandCat used externally supplied exploits and began developing its own attack platform, Sharpa, in October 2018. Repeated operational security failures exposed its malware development environment, infrastructure, and four zero-day exploits. These failures included enabling antivirus telemetry on development systems, submitting test malware to VirusTotal from operational infrastructure, and embedding a developer-desktop screenshot in a malicious Word test document. The screenshot revealed Sharpa’s interface, Uzbek-language developer notes, and testing infrastructure. Connections between the group’s development systems and infrastructure registered to a military unit in Tashkent supported its attribution to the SSS.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Uzbekistan-based customer cluster referenced as also using CHAINSHOT, in discussion of infrastructure overlap linked to Candiru.
Referenced as a threat actor observed using the CHAINSHOT exploit kit; described as linked to Uzbekistan’s State Security Service (SSS) and noted for OPSEC errors exposing zero-days.
A Uzbekistan-linked espionage threat actor tied to the State Security Service, using purchased zero-day exploits and the Chainshot malware to target victims in the Middle East, while developing its own platform called Sharpa.
Mentioned only to clarify that a separate zero-day vendor, not Volodya, supplied a zero-day used by this APT.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.