PurpleHaze is a China-nexus cyberespionage activity cluster, also reported as Vixen Panda, active in intrusions and reconnaissance from at least June 2024 through March 2025. It has been linked with high confidence to China-nexus activity, while technical and infrastructure overlaps connect portions of the cluster only loosely to APT15 and UNC5174; these overlaps do not establish that PurpleHaze is identical to either group. The cluster targeted more than 70 organizations globally, including a South Asian government-supporting entity, a European media organization, cybersecurity-vendor infrastructure, and an IT logistics provider. Reported victim sectors include government, manufacturing, financial services, telecommunications, research, media, and IT services. PurpleHaze conducted reconnaissance of internet-facing systems and used exploitation of edge-device vulnerabilities for initial access, including a chained Ivanti Cloud Services Appliance attack reportedly occurring before public disclosure. Post-compromise activity included deployment of the GoReShell/GOREVERSE reverse-SSH backdoor family on Windows and Linux, use of SSH keys and WebSocket-based command-and-control communications, and Operational Relay Box infrastructure managed from China to conceal operational infrastructure. Operators also used publicly available security tools, obfuscation and packing, timestomping, and log-removal activity to hinder detection and forensic analysis. ShadowPad activity, including ScatterBrain-obfuscated variants, was observed in the broader related campaign, but attribution of all ShadowPad activity to PurpleHaze is not established. The cluster’s dominant assessed objective is intelligence collection and strategic pre-positioning.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
CVE-2024-24919 affects Check Point Quantum and was independently exploited by PurpleHaze and Fox Kitten.
QUIRSO confirmed today, August 12, 2026, that threat actors have been actively exploiting CVE-2026-59310 (CVSS 9.8), a directory traversal vulnerability in VMware vCenter, following an incident response engagement that revealed attacker activity beginning as early as August 3, just five days after Broadcom publicly disclosed the flaw.
16 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-linked activity cluster cited as independently exploiting CVE-2024-24919 in Check Point Quantum gateways.
A China-nexus actor independently exploiting the Check Point Quantum gateway vulnerability CVE-2024-24919.
Referenced as a previously associated group for the reverse_ssh tunneling tool seen in this exploitation activity; the article does not attribute the current campaign directly to PurpleHaze.
Referenced as a threat cluster previously reported targeting a South Asian government-supporting entity using the GoReShell backdoor and reverse SSH functionality.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.