China-Backed Hackers Target SentinelOne in 'PurpleHaze' Attack Spree
ID: baf1f074-f622-5c29-b29a-70585d3969bf
STIX ID: report--baf1f074-f622-5c29-b29a-70585d3969bf
Feed Name: Dark Reading
Date Published: 2025-06-09
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
SentinelOne's SentineLabs reported that China-linked actors (APT15 and UNC5174) conducted an eight-month campaign—tracked as PurpleHaze and ShadowPad—targeting cybersecurity vendors and about 70 organizations; tactics included Internet-accessible server reconnaissance, ShadowPad backdoor deployment, exploitation of Ivanti cloud vulnerabilities (CVE-2024-8963 and CVE-2024-8190) shortly before public disclosure, and compromise of a third‑party logistics provider, with SentinelOne urging transparency and coordinated incident response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
