logo

China-Backed Hackers Target SentinelOne in 'PurpleHaze' Attack Spree

ID: baf1f074-f622-5c29-b29a-70585d3969bf

STIX ID: report--baf1f074-f622-5c29-b29a-70585d3969bf

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2025-06-09

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

SentinelOne's SentineLabs reported that China-linked actors (APT15 and UNC5174) conducted an eight-month campaign—tracked as PurpleHaze and ShadowPad—targeting cybersecurity vendors and about 70 organizations; tactics included Internet-accessible server reconnaissance, ShadowPad backdoor deployment, exploitation of Ivanti cloud vulnerabilities (CVE-2024-8963 and CVE-2024-8190) shortly before public disclosure, and compromise of a third‑party logistics provider, with SentinelOne urging transparency and coordinated incident response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.