A Wake-Up Call for the Cybersecurity Industry
In a stark reminder that cybersecurity vendors are increasingly in the crosshairs, SentinelOne has disclosed a wide-ranging cyber espionage campaign attributed to China-linked threat actors. Although the attackers failed to breach SentinelOne itself, their attempt, coupled with confirmed compromises at over 70 other global organisations, highlights the growing boldness and sophistication of state-backed threat groups.
The Bigger Picture Behind the SentinelOne Targeting
Between July 2024 and March 2025, a set of partially connected intrusions was uncovered by SentinelOne’s researchers. The targeting spanned sectors as diverse as government, finance, manufacturing, media, research, telecommunications, and logistics. Among the most notable victims were:
- A South Asian government agency
- A leading European media organisation
- An IT logistics provider managing hardware for SentinelOne
- Dozens of additional organisations across critical infrastructure and private industry
These intrusions, tracked under the labels PurpleHaze and ShadowPad, were attributed with high confidence to China-nexus actors, some of whom are linked to groups such as APT15 and UNC5174.
Mapping the Intrusion Clusters
SentinelOne identified six distinct but overlapping activity clusters, labelled A through F:
- Activity A: June 2024 – Breach of a South Asian government entity, deploying ShadowPad malware obfuscated via ScatterBrain
- Activity B: July 2024–March 2025 – Global intrusions across 70+ organisations
- Activity C: Early 2025 – Intrusion into SentinelOne’s IT hardware supplier
- Activity D: October 2024 – Follow-up attack on the original government target, deploying the GoReShell backdoor
- Activity E: October 2024 – Reconnaissance of SentinelOne’s internet-facing server
- Activity F: September 2024 – Breach of a European media organisation, also using GoReShell and THC tools
While Activity E marked a failed attempt against SentinelOne’s own server, Activity C—compromising a logistics vendor and posed a serious supply chain risk, potentially allowing attackers to tamper with employee laptops or images before deployment.
Tools of the Trade: ShadowPad, GoReShell, and THC Utilities
ShadowPad remains a hallmark of Chinese state-sponsored operations, offering modular post-exploitation capabilities. In these campaigns, it was paired with GoReShell, a Go-based reverse shell leveraging SSH tunnels for persistence and stealth. Notably, this was the first known use of tools developed by “The Hacker’s Choice” (THC) by a nation-state group; a significant development in the weaponisation of open-source security utilities.
Threat actors also exploited two Ivanti vulnerabilities (CVE-2024-8963 and CVE-2024-8190) before public disclosure, underscoring their access to zero-day or near-zero-day intelligence.
The Role of UNC5174 and China’s Cyber Playbook
SentinelOne links several of these clusters – particularly those involving supply chain and zero-day exploitation – to UNC5174, a contractor group reportedly aligned with China’s Ministry of State Security. Known for facilitating initial access and selling it to other actors, UNC5174’s infrastructure and tactics suggest a well-orchestrated campaign aimed at long-term espionage and disruption.
The use of ORB (Operational Relay Box) networks operated from China further bolsters attribution.
Security Vendors Are Not Immune
The campaign illustrates a critical lesson: cybersecurity companies are not exempt from targeting – in fact, they are premium targets. With deep visibility into customer networks and privileged access to sensitive data and infrastructure, vendors like SentinelOne offer adversaries a potential foothold into a much broader set of victims.
Had the attacker successfully compromised SentinelOne, they might have exploited trusted channels to distribute malware, compromise OS images, or harvest employee location data through pre-deployment hardware.
Staying Vigilant in a Shifting Threat Landscape
As cyber espionage campaigns grow in scope and stealth, organisations, especially those in the cybersecurity supply chain, must adopt a layered defense approach, including:
- Third-party risk assessments
- Continuous monitoring of vendor access
- Zero trust implementation
- Timely patching of perimeter systems
- Detection of advanced tooling and dual-use software
This campaign is a potent reminder that defenders are now targets, and that protecting the protectors must be part of any serious cyber defense strategy. As state-sponsored groups continue to evolve, the industry must remain agile, proactive, and deeply collaborative in response.
Need help tightening your cyber defences? Talk to one our team today for expert guidance and tailored support!