SentinelOne has uncovered reconnaissance attempts against its infrastructure by a China-linked threat actor dubbed PurpleHaze. The cybersecurity firm first detected this threat during a 2024 intrusion targeting an organization that previously provided hardware logistics services for SentinelOne employees.
Security researchers Tom Hegel, Aleksandar Milenkoski, and Jim Walter identified PurpleHaze as having loose connections to APT15, a state-sponsored group also known as Flea, Nylon Typhoon, Playful Taurus, Royal APT, and Vixen Panda.
## Sophisticated Attack Methods
The threat actors targeted a South Asian government-supporting entity in October 2024, employing:
– An operational relay box (ORB) network
– A Windows backdoor called GoReShell written in Go
– Repurposed open-source tools to establish reverse SSH connections
“The use of ORB networks is a growing trend among these threat groups, since they can be rapidly expanded to create a dynamic and evolving infrastructure that makes tracking cyberespionage operations and their attribution challenging,” the researchers noted.
## Earlier Attacks Using ShadowPad
The same South Asian entity was previously targeted in June 2024 with ShadowPad (aka PoisonPlug), a backdoor commonly used by Chinese espionage groups and considered a successor to PlugX. These ShadowPad artifacts were obfuscated using a custom compiler called ScatterBrain.
The ScatterBrain-obfuscated ShadowPad has reportedly been used against over 70 organizations across manufacturing, government, finance, telecommunications, and research sectors, likely by exploiting vulnerabilities in Check Point gateway devices.
## Multiple Threat Vectors
SentinelOne faces threats from multiple directions:
1. **North Korean IT Workers**: Approximately 360 fake personas and over 1,000 job applications from North Korea-aligned actors attempting to infiltrate the company.
2. **Ransomware Operators**: Targeting SentinelOne and other security platforms to test their malware’s ability to evade detection.
3. **Underground Economy**: An active market for buying, selling, and renting access to enterprise security offerings on messaging apps and forums like XSS.is, Exploit.in, and RAMP.
## Innovative Threat Tactics
The Nitrogen ransomware group, believed to be operated by a Russian national, employs a particularly sophisticated approach. Rather than targeting insiders or using stolen credentials, Nitrogen impersonates legitimate companies by:
– Setting up lookalike domains
– Creating spoofed email addresses
– Building cloned infrastructure
– Purchasing official licenses for security products
“This kind of social engineering is executed with precision,” researchers explained. “Nitrogen typically targets small, lightly vetted resellers – keeping interactions minimal and relying on resellers’ inconsistent KYC practices to slip through the cracks.”
