China’s PurpleHaze Cyber Blitz: SentinelOne and 70 Others Under Siege!

SentinelOne security researchers revealed that China-nexus threat actors, tied to a cluster called PurpleHaze, have been targeting various sectors, including manufacturing and telecommunications. Among the victims was an IT services company managing hardware logistics for SentinelOne. It seems the hackers were not just after cookies, but the whole cookie jar!

Pro Dashboard

Hot Take:

In a shocking twist that no one saw coming, cybercriminals have decided to target everyone, everywhere, all at once. SentinelOne is the latest in a long line of victims, proving once and for all that cyber espionage is truly the world’s worst game of tag. You’re it, SentinelOne!

Key Points:

  • Reconnaissance activity linked to China-nexus threat actors targeted SentinelOne and over 70 organizations globally between July 2024 and March 2025.
  • The attacks are attributed to the PurpleHaze threat cluster, overlapping with known Chinese espionage groups APT15 and UNC5174.
  • Six distinct activity clusters, labeled A to F, were identified, showcasing the widespread nature of the attacks.
  • ShadowPad and GoReShell malware were deployed in some of these intrusions.
  • Tools developed by The Hacker’s Choice were used for the first time by state-sponsored actors.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?