A sweeping cyber-espionage campaign attributed to a China-linked hacking collective has targeted over 70 organizations across diverse sectors—this according to a detailed analysis by cybersecurity researchers. The campaign spanned from July 2024 through March 2025 and included attacks on government bodies, media outlets, critical infrastructure, and private companies—including industry-leading cybersecurity firm SentinelOne
Key Findings from SentinelLABS
- Timeframe & Scope: The campaign unfolded over nine months, impacting organizations in North America, Europe, and Asia Pacific .
- Intrusion Techniques: Tactics included deploying ShadowPad—a known modular backdoor—obfuscated through a new method dubbed “ScatterBrain.” Earlier intrusions used tools like GoReShell, a Go-based reverse shell leveraging SSH tunnels .
- Shared Infrastructure: Activities overlapped significantly with previously tracked clusters (DarkHaze/PurpleHaze/Vixen Panda), indicating sustained campaigns managed by the same China-linked actors.
Prominent Victims
- Government & Media: A leading European media organization was targeted in September 2024, followed by a government entity in June 2024—both hit with backdoors and advanced remote-access tools
- Security Firms: SentinelOne reported it thwarted attacks targeting its own research infrastructure and those of its suppliers, suggesting a direct effort by the hackers to undermine cybersecurity capabilities
Group Attribution & Motives
The campaign has been tentatively tied to UNC5174 (a.k.a. Uteus or Uetus) by SentinelOne, and to PurpleHaze/Vixen Panda by SentinelLABS—groups believed to operate or coordinate under Chinese state influence. Motivations seem centered on intelligence collection, supply-chain penetration, and developing persistent access channels
Broader Impacts & Recommendations
- Widespread Exposure: The victims span critical infrastructure, media, government entities, and cybersecurity vendors—highlighting the threat’s reach.
- Supply-Chain Vulnerabilities: Supply chain pathways were exploited to propagate backdoors into major organizations, underscoring the need for stronger vendor and third-party risk management.
- Evolving Threat Tactics: Hackers used obfuscation and custom tools to avoid detection—emphasizing the need for proactive defense strategies, including advanced threat-hunting and zero-trust architectures
What Organizations Should Do Now
- Audit Supply-Chain Risk: Conduct thorough security reviews of third-party vendors and partners.
- Strengthen Detection Systems: Implement anomaly-based detection and robust logging to spot early-stage infections.
- Apply Critical Patches: Ensure timely patching—particularly for widely known vulnerabilities in enterprise systems.
- Collaborate on Threat Intel: Share indicators of compromise across sectors to strengthen collective defense.
This extensive cyber-espionage operation—targeting more than 70 entities worldwide—highlights a growing trend: increasingly sophisticated, state-aligned hacking groups are targeting infrastructure and security providers to elevate intelligence-gathering capabilities. With ShadowPad and ScatterBrain tactics spreading through supply chains, organizations must bolster cyber hygiene, reinforce supply-chain vetting, and lean into collaborative threat intelligence. In the face of evolving threats, a proactive and coordinated cybersecurity posture remains essential.
Please subscribe to the Newsletter so that you do not miss any critical update
