logo

Chinese spy crew appears to be preparing for conflict by backdooring 75+ critical orgs

ID: 24583c96-319c-5649-968f-138e3aa2a6f2

STIX ID: report--24583c96-319c-5649-968f-138e3aa2a6f2

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2025-06-09

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

SentinelLABS uncovered a China-linked cyber-espionage campaign called "PurpleHaze" active between July 2024 and March 2025 that used ShadowPad (obfuscated with ScatterBrain variants) and GOREVERSE backdoors to compromise over 70 organizations across government, media, IT services, telecoms and research. The attackers exploited two Ivanti vulnerabilities (CVE-2024-8963 and CVE-2024-8190) around September 2024, targeted supply-chain routes including an IT services provider and tried reconnaissance against SentinelOne itself, suggesting strategic pre-positioning for conflict by suspected APT15/UNC5174-linked groups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.