Target Industry
Targeted sectors include government entities, media companies, technology, healthcare, finance, and critical infrastructure.
Overview
A recent report by SentinelLABS has revealed a significant cyber espionage campaign attributed to a China-linked threat actor, targeting over 70 global organisations across various sectors from July 2024 to March 2025. The operations, identified as ‘PurpleHaze’ and ‘ShadowPad’, involved sophisticated tactics including the use of advanced malware and exploitation of zero-day vulnerabilities.
PurpleHaze: Includes intrusions into various targets, such as a South Asian government entity and a European media organisation. ShadowPad: Involves malware targeting multiple sectors globally, including manufacturing, government, finance, telecommunications, and research. The findings underscore the persistent threat posed by state-sponsored actors and the critical need for enhanced cybersecurity measures across all sectors.
Impact
The impact is significant, with organisations facing heightened threats from sophisticated cyberattacks, necessitating stronger cybersecurity measures. The intrusions can lead to disruptions in organisational operations, affecting productivity and potentially causing financial losses. Being targeted by cyber espionage can harm a company’s reputation, leading to loss of customer trust and potential business opportunities.
Exploitation
Cyber espionage is typically exploited through a variety of sophisticated techniques. These techniques include phishing attacks, malware, Advanced Persistent Threats (APTs), exploiting vulnerabilities, insider threats, and social engineering.
Containment, Mitigations & Remediations
To mitigate risks, organisations should adopt a multi-layered security approach, including regular software updates, robust access controls, and incident response plans. Collaboration with cybersecurity firms and participation in threat intelligence sharing platforms can further strengthen defences.
Threat Landscape
The targeting of over 70 organisations by a China-linked cyber espionage group underscores the evolving nature of cyber threats and the need for robust cybersecurity measures. As these threats continue to grow in sophistication, organisations must remain vigilant and proactive in their defence strategies to safeguard sensitive information and critical infrastructure.
Threat Group
The threat actor group involved in this campaign is associated with multiple aliases, including PurpleHaze and APT15 (also known as Nylon Typhoon). These groups are believed to have strong ties to the Chinese government and are known for their sophisticated cyber operations targeting high-value entities. The use of advanced malware, such as ShadowPad, and tactics that align with broader Chinese APT patterns complicate attribution and enhance operational stealth.
The primary motivation behind the activities of this China-linked cyber espionage group appears to be geopolitical in nature, focusing on gathering intelligence that can bolster China’s strategic interests. The group’s objectives include stealing sensitive information, intellectual property, and potentially preparing for future conflicts by compromising critical infrastructure.
Further Information
Follow the Smoke | China-nexus Threat Actors Hammer At the Doors of Top Tier Targets | SentinelOne













