SandCat is a nation-state threat actor assessed to be linked to Uzbekistan’s State Security Service (SSS), formerly known as the National Security Service of Uzbekistan. The group has been associated with cyber-espionage activity and the deployment of Windows malware and zero-day exploits against targets in the Middle East. Reporting has tied SandCat to use of the CHAINSHOT exploit kit and to an internally developed attack platform called Sharpa. SandCat became notable for repeated operational security failures that exposed elements of its development and operational infrastructure, malware testing activity, and exploit usage. These mistakes reportedly included using security software with telemetry enabled on development systems, uploading test artifacts from operational infrastructure, and inadvertently exposing development screenshots containing Uzbek-language notes and details of internal tooling. Investigators linked the group to Uzbekistan through infrastructure associated with an official Uzbek domain and registration data tied to a military unit in Tashkent that has been connected to SSS-related forensic activity. The group has been observed using zero-day exploits for initial compromise and malware delivery, and additional reporting indicates it relied on externally sourced exploits rather than exclusively in-house exploit development. SandCat’s activity demonstrates capabilities consistent with initial access, privilege escalation, persistence, post-exploitation, and espionage-oriented collection. It has also been associated with malware deployment and operational infrastructure management characteristic of a state security service–linked intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Uzbekistan-based customer cluster referenced as also using CHAINSHOT, in discussion of infrastructure overlap linked to Candiru.
Referenced as a threat actor observed using the CHAINSHOT exploit kit; described as linked to Uzbekistan’s State Security Service (SSS) and noted for OPSEC errors exposing zero-days.
A Uzbekistan-linked espionage threat actor tied to the State Security Service, using purchased zero-day exploits and the Chainshot malware to target victims in the Middle East, while developing its own platform called Sharpa.
Mentioned only to clarify that a separate zero-day vendor, not Volodya, supplied a zero-day used by this APT.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.