China’s PurpleHaze Cyber Blitz: SentinelOne and 70 Others Under Siege!
SentinelOne security researchers revealed that China-nexus threat actors, tied to a cluster called PurpleHaze, have been targeting various sectors, including manufacturing and telecommunications. Among the victims was an IT services company managing hardware logistics for SentinelOne. It seems the hackers were not just after cookies, but the whole cookie jar!

Hot Take:
In a shocking twist that no one saw coming, cybercriminals have decided to target everyone, everywhere, all at once. SentinelOne is the latest in a long line of victims, proving once and for all that cyber espionage is truly the world’s worst game of tag. You’re it, SentinelOne!
Key Points:
- Reconnaissance activity linked to China-nexus threat actors targeted SentinelOne and over 70 organizations globally between July 2024 and March 2025.
- The attacks are attributed to the PurpleHaze threat cluster, overlapping with known Chinese espionage groups APT15 and UNC5174.
- Six distinct activity clusters, labeled A to F, were identified, showcasing the widespread nature of the attacks.
- ShadowPad and GoReShell malware were deployed in some of these intrusions.
- Tools developed by The Hacker’s Choice were used for the first time by state-sponsored actors.
Already a member? Log in here