SentinelLABS disrupted multiple China-nexus cyberespionage campaigns between June 2024 and March 2025 targeting SentinelOne, a South Asian government entity, a European media organization, and more than 70 other victims. The ShadowPad and PurpleHaze clusters used chained zero-days in edge appliances, including CVE-2024-8963 and CVE-2024-8190, alongside ShadowPad malware protected by ScatterBrain/ScatterBee obfuscation, the Go-based GOREshell reverse-SSH backdoor, Nimbo-C2, operational relay box networks, and log removal. SentinelOne reported that it was not compromised.
A joint Tenable-SentinelOne review shows that this activity reflects a broader cross-actor pattern: 93 CVE-to-actor attribution pairs across 82 vulnerabilities converged on all seven identified edge-device vendors, despite only 21% overlap in the CVEs tracked independently. Twelve flaws have confirmed exploitation by multiple China-, Russia-, DPRK-, or Iran-linked groups and ransomware operators. F5, Citrix, and Ivanti EPMM and Connect Secure deployments face recurring exposure and exploitation; organizations should prioritize edge-device patching, disable unnecessary features, continuously monitor remote-access systems, and use segmentation and other defense-in-depth controls to limit lateral movement after a breach.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
SentinelLABS identified and disrupted a ShadowPad intrusion at an IT services and logistics company that managed hardware for SentinelOne employees. SentinelOne reported no resulting compromise of its own assets.
A China-linked actor exploited CVE-2024-8963 and CVE-2024-8190 against an Ivanti Cloud Services Appliance and collected SSH keys and other stored credentials. The activity was associated with the PurpleHaze cluster and UNC5174-linked access brokering.
SentinelLABS observed and countered a PurpleHaze reconnaissance operation targeting SentinelOne. SentinelOne found no evidence that its infrastructure, software, or hardware assets were compromised.
ShadowPad and PurpleHaze activity clusters conducted intrusions against more than 70 organizations across manufacturing, government, finance, telecommunications, and research, including a South Asian government entity and a European media organization. SentinelLABS attributed the activity with high confidence to China-nexus actors, with links to APT15 and UNC5174.
Tenable and SentinelOne analyzed 93 CVE-actor attribution pairs involving approximately 39 threat actors and identified 82 distinct CVEs. The analysis found 12 vulnerabilities with confirmed exploitation by multiple state-linked or criminal actor nexuses, including China-linked PurpleHaze and Iran-linked Fox Kitten exploitation of CVE-2024-24919.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 53 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.