HomeSecurityHackers Target SentinelOne Infrastructure and Customers

Hackers Target SentinelOne Infrastructure and Customers

Cybersecurity firm SentinelOne announced that Chinese hackers PurpleHaze attempted to collect information about its infrastructure and some of its important customers.

SentinelOne hackers

" We first identified this threat during a breach in 2024, at an organization that previously provided hardware logistics services to SentinelOne employees ," security experts Tom Hegel, Aleksandar Milenkoski and Jim Walter said in a report published Monday.

PurpleHaze reportedly has some loose connections to a state-backed Chinese group known as APT15.

See also: Are Scattered Spider hackers behind the attack on Marks & Spencer?

The same group has been recorded targeting an anonymous entity providing support to a South Asian government organization, using an operational relay box (ORB) network and a malicious Windows backdoor program called GoReShell.

This implant, written in the Go, leverages an open source tool called reverse_ssh to create reverse SSH connections, allowing attackers to remotely control target systems.

The researchers noted that the use of ORB networks is an increasingly common practice among these threat groups, as they allow for the rapid deployment of a flexible and changing infrastructure, making it difficult to identify and attribute responsibility for cyberespionage activities.

Further investigation revealed that the same South Asian organization had been attacked in June 2024 using ShadowPad (also known as PoisonPlug), a notorious backdoor widely used by Chinese espionage groups. ShadowPad is considered the successor to PlugX, another well-known malicious tool.

Although ShadowPad has also recently been used to install ransomware, the exact motives for this attack remain unclear. Technical evidence suggests that the variant of ShadowPad used was modified via a special compiler called ScatterBrain.

See also: Storm-1977 hackers target cloud infrastructure in the education sector

Although it is unclear whether the June attacks are related to the actions of the PurpleHaze hackers, experts believe it is likely that the same perpetrator is behind both operations.

The sophisticated ShadowPad, in conjunction with ScatterBrain, was allegedly used in breaches affecting over 70 organizations, possibly by exploiting a known vulnerability (N-day) in CheckPoint. One of the victims of these attacks was the organization that was responsible for hardware logistics services for SentinelOne employees at the time. However, the cybersecurity company said it had not seen any further breaches within its own systems.

Hackers Target SentinelOne Infrastructure and Customers

However, the threats are not limited to China. SentinelOne revealed that it has also detected infiltration attempts by individuals associated with North Korea. Specifically, there have been attempts to recruit for positions within the company — even on the SentinelLabs analyst team — through the use of approximately 360 fake identities and 1,000 job applications.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Additionally, ransomware attacks have begun to directly target SentinelOne and similar security companies that focus on enterprise protection, seeking to gain access to their tools to assess whether they can detect or prevent malicious activity.

See also: Storm-1977 hackers target cloud infrastructure in the education sector

This trend is fueled by an illicit market that has developed around the sale, rental, or purchase of access to enterprise security software, often through messaging apps and platforms such as the XSS[.]is, Exploit[.]in , and RAMP.

“A whole range of services have emerged within this ecosystem,” the analysts said, “including so-called “EDR Testing-as-a-Service” services, which allow attackers to test the effectiveness of their malware against threat detection.”

These attempted attacks show that leading companies in the cybersecurity are being targeted by hackers.

The selection of high-value targets suggests that attackers are likely not only interested in industrial espionage, but may be preparing more sophisticated or destructive attacks. The fact that state groups are focusing on a security solution provider is strategically dangerous, as it can put multiple organizations at risk through the supply chain.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS