Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstalliTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
SentinelOne says a China-nexus activity cluster it tracks as PurpleHaze probed its internet-facing infrastructure and was linked to an intrusion at a former hardware-logistics provider. The company says it found no evidence that its own infrastructure was compromised. The episode is therefore a supply-chain exposure and reconnaissance story—not a confirmed breach of SentinelOne.
What happened to SentinelOne?
SentinelOne says it first became aware of PurpleHaze in 2024, in connection with an intrusion at an organization that had previously provided hardware-logistics services for SentinelOne employees. The security company also observed reconnaissance attempts against its own infrastructure. Its investigation of its infrastructure, software, and hardware assets found no evidence of a secondary compromise. The confirmed supplier exposure does not establish that attackers used the provider to enter SentinelOne’s systems.
SentinelOne described the probes as mapping and evaluating selected internet-facing servers, likely in preparation for possible future actions. That is the company’s assessment of the activity, not proof that an attack was planned or carried out. SecurityWeek’s June 9, 2025 report characterized the reconnaissance effort as spanning the preceding twelve months.
Who or what is PurpleHaze?
PurpleHaze is SentinelOne’s tracking name for an activity cluster, not a publicly established, definitive identity for a single organization. SentinelOne assesses with high confidence that the activity is China-nexus and loosely links it to APT15. The company also reports technical overlaps with multiple publicly reported Chinese APT groups. Shared tools, infrastructure, and access can make those overlaps difficult to interpret, so they do not prove that one specific group conducted every related intrusion.
#1 Best Overall
SentinelOne describes an extensive infrastructure set, including some systems associated with an operational relay box (ORB) network. It says the ORB infrastructure was operated from China and used by several suspected Chinese cyberespionage actors, including APT15. The primary report also says the company’s investigation into whether the June 2024 ShadowPad activity and later PurpleHaze activity involved the same cluster was ongoing; it did not rule out that possibility, while noting that tools, infrastructure, or access may be shared or transferred. SentinelLABS’ report provides the company’s attribution and infrastructure assessment.
What are ShadowPad and GoReShell?
ShadowPad
SentinelOne describes ShadowPad as a modular backdoor used by multiple suspected China-nexus actors. In the activity it reported, some ShadowPad samples were obfuscated with ScatterBrain, which SentinelOne calls an evolution of ScatterBee. SentinelOne notes that Google Threat Intelligence Group had observed ScatterBrain-obfuscated ShadowPad samples since 2022 and attributed them to clusters associated with suspected APT41. That history is relevant technical context, not evidence that APT41 carried out the PurpleHaze activity.
GoReShell
GoReShell is a Go-based Windows backdoor that SentinelOne says uses reverse SSH functionality to connect to attacker-controlled endpoints. The report connects it with PurpleHaze infrastructure and activity. The use of the same tool or infrastructure can inform an investigation, but by itself does not settle who was operating it.
Recommended Free Tools
How broad was the reported activity?
SentinelOne reports that ShadowPad-obfuscated intrusions affected more than 70 organizations between July 2024 and March 2025. The company identified victims in manufacturing, government, finance, telecommunications, and research. This is SentinelOne’s 2025 figure for the broader intrusion set; it is not a count of confirmed SentinelOne customers or organizations compromised through the logistics provider.
Rank #3
SentinelOne says exploitation of an n-day vulnerability in Check Point gateway devices was the initial foothold in most of those organizations. “Most” matters: the report does not say this was the entry route in every case. An n-day vulnerability is one that is already known, rather than a previously unknown zero-day; the report does not establish that every affected organization was vulnerable in the same way.
What the timeline shows—and does not show
| Period | Reported event | What it establishes |
|---|---|---|
| June 2024 | SentinelOne observed ShadowPad-related activity targeting a South Asian government entity that was targeted again in October. | The report documents activity against that entity; it does not establish that this activity and PurpleHaze were the same cluster. |
| 2024 | PurpleHaze came to SentinelOne’s attention in connection with an intrusion at a former hardware-logistics provider. | The supplier relationship was an exposure concern; SentinelOne says its review found no evidence of a secondary compromise of its own infrastructure. |
| July 2024–March 2025 | SentinelOne identified more than 70 organizations affected by intrusions involving ScatterBrain-obfuscated ShadowPad. | This is the period and count SentinelOne reported for the broader intrusion set, not the number of victims in the logistics-provider incident. |
| October 2024 | The South Asian government entity was targeted again, SentinelOne says. | The later targeting does not resolve whether the June activity and PurpleHaze overlapped. |
| June 9, 2025 | SecurityWeek published its account of SentinelOne’s disclosure. | Its “year-long” characterization describes SentinelOne’s reconnaissance efforts as spanning the prior twelve months. |
The distinction between the provider incident, reconnaissance directed at SentinelOne, and the broader ShadowPad victim set is important. SentinelOne has not said that all of these events shared one operator or that the broader victims were reached through the supplier.
Rank #4
Why a supplier incident matters even without a confirmed breach
A supplier can hold information about devices, procurement, shipping, or employee workflows even when it does not have direct access to a customer’s core network. That creates questions about exposure and access paths; it does not automatically mean the customer’s systems were compromised. SentinelOne says it remained unclear whether the perpetrators focused only on the logistics provider or intended to reach its clients.
SentinelOne explains why cyber companies can be attractive targets: “When adversaries compromise a security company, they don’t just breach a single environment—they potentially gain insight into how thousands of environments and millions of endpoints are protected.” The company presents this as a reason to take targeting seriously, not as a claim that it suffered such a compromise in this incident.
Best Value
What organizations should review after a supply-chain incident
SentinelOne recommends treating a supplier incident as a trigger to check both technical controls and the business workflows that could expose devices or sensitive information. Its guidance includes:
- Identify service providers, including former providers, that handled sensitive employee devices or logistics information.
- Review asset inventories and procurement workflows to confirm which devices were ordered, shipped, received, and assigned during the relevant period.
- Check operating-system images, onboarding deployment scripts, and segmentation policies for unintended changes or paths into internal systems.
- Share campaign-level threat intelligence with vendor-management, logistics, and physical-operations teams, not only security analysts.
- Improve threat context in asset-attribution workflows so teams can connect supplier and shipment information with the devices and systems they manage.
- Expand supply-chain threat models to account for indirect exposure through logistics and other service relationships.
These checks do not presume that a supplier has provided attackers access to a customer network. They help determine what information or equipment the supplier could have exposed, what connections existed, and whether the customer’s own records and controls show signs of follow-on activity.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

