Follow the Smoke | China-nexus Threat Actors Hammer At the Doors of Top Tier Targets
ID: adadb6ac-2b33-5df0-9e2e-3113a8ef3aa5
STIX ID: report--adadb6ac-2b33-5df0-9e2e-3113a8ef3aa5
Date Published: 2025-06-09
Date Updated: 2026-07-27
Author: Aleksandar Milenkoski & Tom Hegel
SentinelLABS documents coordinated intrusion activity from June 2024 to March 2025—tracked as ShadowPad and PurpleHaze—attributing with high confidence to China‑nexus actors who used ShadowPad backdoors and GOREshell reverse-SSH tooling, exploited Ivanti Cloud vulnerabilities (CVE-2024-8963, CVE-2024-8190) including pre-public disclosures, conducted reconnaissance against SentinelOne, exfiltrated sensitive files, and leveraged ORB infrastructure and shared tooling across more than 70 victims worldwide; the report includes detailed TTPs and comprehensive IOCs to support detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
