Home Cyber Security News New Report Reveals Chinese Hackers Targeted to Breach SentinelOne Servers

New Report Reveals Chinese Hackers Targeted to Breach SentinelOne Servers

0

A newly published technical analysis by SentinelLABS has exposed a sophisticated, multi-phase reconnaissance and intrusion campaign orchestrated by Chinese-nexus threat actors, aimed explicitly at SentinelOne’s digital infrastructure between mid-2024 and early 2025.

The operation, tracked under the activity clusters “PurpleHaze” and “ShadowPad,” reflects an alarming trend: advanced persistent threat (APT) groups are increasingly prioritizing cybersecurity vendors as high-value targets, given their critical defensive roles and privileged access across global clients.

Technical Overview

According to SentinelLABS Report, the campaign’s timeline spans from July 2024 through March 2025, involving a web of related intrusions.

These include a June 2024 ShadowPad malware attack on a South Asian governmental IT entity; subsequent attacks on European media, logistics organizations, and over 70 victims globally in sectors such as manufacturing, finance, telecom, and research.

ShadowPad activity, June 2024 – March 2025

Notably, the attackers targeted an IT logistics provider supporting SentinelOne staff, and conducted extensive remote reconnaissance on internet-exposed SentinelOne servers.

The PurpleHaze and ShadowPad activity clusters have been attributed with high confidence to Chinese cyberespionage actors, exhibiting operational and malware overlaps with the widely tracked APT15 (Ke3Chang, Nylon Typhoon) and UNC5174 groups.

While no compromise of SentinelOne’s core infrastructure was detected, the attackers’ persistent efforts underscore their intent to both map defensive perimeters and potentially exploit supply chain relationships.

Technical Indicators

The attackers leveraged a blend of bespoke and open-source malware including ShadowPad a modular, closed-source backdoor platform and the GOREshell backdoor (a Go-based SSH reverse tunneling tool).

‘The infrastructure and malware deployment strategies demonstrated advanced operational security: C2 communications used obfuscated DNS over HTTPS, domain registration and IP address overlaps, and abuse of vulnerable services through chained ransomware and credential harvesting.

PowerShell exfiltration script

One notable cluster involved exploiting critical vulnerabilities in Ivanti Cloud Services Appliance (CVE-2024-8963, CVE-2024-8190) ahead of public disclosure, followed by deployment of GOREshell.

Attackers employed DLL hijacking on vulnerable VMWare executables, masqueraded malicious payloads under legitimate service names, and deployed custom log-erasure utilities (derived from THC’s clear13) to thwart forensics.

Remote reconnaissance focused on SentinelOne’s externally exposed servers revealed coordinated use of VPS proxies, domain masquerading (e.g., sentinelxdr[.]us), and synchronized infrastructure updates.

SentinelLABS’ telemetry and active hunting identified and neutralised these threats swiftly, but the investigation highlights the substantial risks posed by persistent APT reconnaissance.

This campaign spotlights a broader strategic reality: cybersecurity vendors are becoming prime targets for nation-state actors who seek visibility into security tooling, adversary disruptions, and potential downstream access to clients.

SentinelLABS’ disclosure aims to destigmatize industry-wide sharing of technical indicators and to bolster collaborative defense against rapidly adapting APT actors.

The company urges proactive threat intelligence exchange and real-time incident response coordination as key safeguards.

Indicators of Compromise (IOCs)

TypeValueNote
SHA-1f52e18b7c8417c7573125c0047adb32d8d813529ShadowPad (AppSov.exe)
SHA-1411180c89953ab5e0c59bd4b835eef740b550823GOREshell (snapd)
SHA-1cb2d18fb91f0cd88e82cb36b614cfedf3e4ae49bGOREshell (glib-2.0.dll)
SHA-15ee4be6f82a16ebb1cf8f35481c88c2559e5e41aShadowPad
SHA-14896cfff334f846079174d3ea2d541eec72690a0Nimbo-C2 agent (PfSvc.exe)
Domaindownloads.trendav[.]vipGOREshell C2 server
Domainnews.imaginerjp[.]comShadowPad C2 server
Domainsentinelxdr[.]usMasquerades as SentinelOne infrastructure
Domaindscriy.chtq[.]netShadowPad C2 server
Domaintatacom.duckdns[.]orgC2 server, telecom-themed
IP Address65.38.120[.]110ShadowPad C2 server
IP Address142.93.214[.]219GOREshell C2 / infrastructure
IP Address103.248.61[.]36Malware hosting
URLshttps[://]45.13.199[.]209/rss/rss.phpExfiltration endpoint

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Update

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Exit mobile version