Mango Sandstorm is an advanced persistent threat (APT) that has been active since at least 2013, targeting government and military organizations in South Asia. It is believed to be a state-sponsored attacker group with ties to the Indian intelligence agency RAW. The APT uses various tactics such as spear phishing emails, watering hole attacks, and exploiting vulnerabilities in software to gain access to sensitive information. Mango Sandstorm has been linked to several high-profile cyber espionage incidents including Operation ShadowHammer which targeted the Indian military's communication systems.
Techniques, tactics and practices:
Mango Sandstorm is an advanced persistent threat that uses various tactics such as spear phishing emails, watering hole attacks, exploiting vulnerabilities in software to gain access to sensitive information. It also employs techniques like social engineering and malware development to achieve its objectives. The group has been known for targeting government and military organizations in South Asia using advanced tools and technologies that make it difficult to detect their activities.