A sweeping cyber-espionage campaign attributed to a China-linked hacking collective has targeted over 70 organizations across diverse sectors—this according to a detailed analysis by cybersecurity researchers. The campaign spanned from July 2024 through March 2025 and included attacks on government bodies, media outlets, critical infrastructure, and private companies—including industry-leading cybersecurity firm SentinelOne

Key Findings from SentinelLABS

  • Timeframe & Scope: The campaign unfolded over nine months, impacting organizations in North America, Europe, and Asia Pacific .
  • Intrusion Techniques: Tactics included deploying ShadowPad—a known modular backdoor—obfuscated through a new method dubbed “ScatterBrain.” Earlier intrusions used tools like GoReShell, a Go-based reverse shell leveraging SSH tunnels .
  • Shared Infrastructure: Activities overlapped significantly with previously tracked clusters (DarkHaze/PurpleHaze/Vixen Panda), indicating sustained campaigns managed by the same China-linked actors.

Prominent Victims

  • Government & Media: A leading European media organization was targeted in September 2024, followed by a government entity in June 2024—both hit with backdoors and advanced remote-access tools
  • Security Firms: SentinelOne reported it thwarted attacks targeting its own research infrastructure and those of its suppliers, suggesting a direct effort by the hackers to undermine cybersecurity capabilities

Group Attribution & Motives

The campaign has been tentatively tied to UNC5174 (a.k.a. Uteus or Uetus) by SentinelOne, and to PurpleHaze/Vixen Panda by SentinelLABS—groups believed to operate or coordinate under Chinese state influence. Motivations seem centered on intelligence collection, supply-chain penetration, and developing persistent access channels

Broader Impacts & Recommendations

  • Widespread Exposure: The victims span critical infrastructure, media, government entities, and cybersecurity vendors—highlighting the threat’s reach.
  • Supply-Chain Vulnerabilities: Supply chain pathways were exploited to propagate backdoors into major organizations, underscoring the need for stronger vendor and third-party risk management.
  • Evolving Threat Tactics: Hackers used obfuscation and custom tools to avoid detection—emphasizing the need for proactive defense strategies, including advanced threat-hunting and zero-trust architectures

What Organizations Should Do Now

  1. Audit Supply-Chain Risk: Conduct thorough security reviews of third-party vendors and partners.
  2. Strengthen Detection Systems: Implement anomaly-based detection and robust logging to spot early-stage infections.
  3. Apply Critical Patches: Ensure timely patching—particularly for widely known vulnerabilities in enterprise systems.
  4. Collaborate on Threat Intel: Share indicators of compromise across sectors to strengthen collective defense.

This extensive cyber-espionage operation—targeting more than 70 entities worldwide—highlights a growing trend: increasingly sophisticated, state-aligned hacking groups are targeting infrastructure and security providers to elevate intelligence-gathering capabilities. With ShadowPad and ScatterBrain tactics spreading through supply chains, organizations must bolster cyber hygiene, reinforce supply-chain vetting, and lean into collaborative threat intelligence. In the face of evolving threats, a proactive and coordinated cybersecurity posture remains essential.

Please subscribe to the Newsletter so that you do not miss any critical update

Leave a Reply

Your email address will not be published. Required fields are marked *