Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors PurpleHaze

Also known as: Nylon Typhoon, APT28, Fancy Bear, tracked as, drug street names, for decades, UNC5174 by Mandiant, GOREVERSE, Mysterious Elephant, other various outdated aliases, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, Paper Werewolf, Rare Werewolf, Central Asia, DarkGaboon, Vengeful Wolf, Black Owl, Lifting Zmiy, Hoody Hyena, which targets Russian companies, FoxBlade, MDaemon, Zimbra, in addition to Roundcube, Lotus Blossom, Lotus Panda, February 2025, Parisite, Pioneer Kitten, UNC757, FruityArmor, Sofacy, UNK_RemoteRogue, VIXEN PANDA, Ke3Chang, Playful Dragon, Metushy, Lurid, Social Network Team, Royal APT, BRONZE PALACE, BRONZE DAVENPORT, BRONZE IDLEWOOD, NICKEL, G0004, Red Vulture, Mirage, RIVER CASTLE, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code, Rezet, Head Mare, Unicorn, LAUNDRY BEAR, Bronze Elgin

Description

PurpleHaze combines advanced vulnerability exploitation with a broad arsenal of pre‑existing malware to achieve persistence and exfiltration objectives. The actor has repeatedly leveraged recently disclosed CVEs—particularly in Ivanti Cloud Services Appliance, Biotime, MDaemon, Zimbra, and various Office/MDaemon exploits—to gain initial foothold in target environments. Once inside, PurpleHaze deploys a suite of publicly available backdoors, including GOREVERSE (reverse SSH), ShadowPad, DarkGate, BrockenDoor, Remcos, and several custom implants such as Havoc, HanifNet, NeoExpressRAT, and MeshCentral Agent. These backdoors often reside in malicious cloud or container images to maintain persistence on cloud platforms, while the actor also uses living‑off‑the‑land (LoL) techniques—PowerShell, WMI, and scheduled tasks—to avoid detection. The group routinely exfiltrates data over application layer protocols (T1071), via public web services, and through command‑and‑control channels embedded in legitimate cloud platforms. After exfiltration it may encrypt or delete backups with SDelete to cover tracks or deploy Babuk ransomware for monetization. PurpleHaze’s operations display a sophisticated blend of cyber espionage, impact, and financial theft across multiple industry sectors.

Goals & Targeting

Targeted Sectors

Government
Financial services
Defense
Telecommunications
Media
Transportation
Manufacturing
Energy
Information technology
Utilities
Education
Retail
Construction
Healthcare
Aerospace
Critical infrastructure
Aviation
Non profit
Oil gas
Chemical
Mining
Nuclear

Targeted Countries / Regions

CN
RU
TW
KP
US
UA
IL
SY
KR
SA
IN
TR
AE
CA
IR
GB
JP
VN
BR
AU

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 3 days ago

Executive Summary

PurpleHaze is a highly sophisticated China‑linked threat actor that blends public CVE exploitation with readily available backdoors such as GOREVERSE and ShadowPad. The group prioritizes government, critical infrastructure, finance, and telecom targets worldwide through spearphishing, living‑off‑the‑land execution, and cloud/container persistence, routinely inserting ransomware (Babuk) to monetize exfiltration efforts. Its attacks exhibit both espionage motives and clear financial gain objectives.

Goals & Targeting

PurpleHaze's strategic objectives revolve around obtaining sensitive information from high-value targets—including governmental agencies, defense contractors, critical infrastructure operators, and major financial institutions—while simultaneously seizing financial opportunities through ransomware. The actor displays a geographic focus on countries with significant economic or geopolitical importance, spanning North America, Eurasia, the Middle East, and parts of Asia. By embedding themselves in shared supply chains and exploiting public cloud resources, PurpleHaze aims to achieve persistence, stealth, and rapid lateral movement within complex enterprise environments.

Enhanced Description

Key Capabilities

  • Exploitation of software vulnerabilities (CVE-based) including Ivanti Cloud Services Appliance, Biotime, MDaemon, Zimbra, and Office XSS
  • Spearphishing with malicious attachments to deliver backdoors
  • Use of publicly available backdoors: GOREVERSE, ShadowPad, DarkGate, BrockenDoor, Remcos, Havoc, HanifNet, NeoExpressRAT, MeshCentral Agent
  • Living‑off‑the‑land execution via PowerShell, WMI, and scheduled tasks
  • Persistence through malicious cloud or container images in registries
  • Remote service exploitation (RDP, SSH, VPN)
  • Data destruction with SDelete and backup wiping
  • Deployment of Babuk ransomware for monetization
  • Exfiltration over application layer protocols and public web services
  • Use of tunneling tools such as plink and Ngrok for lateral movement and exfiltration
  • Credential dumping with Mimikatz or custom loaders
  • Injection of malicious JavaScript payloads into email clients (SpyPress chain)
  • Hosting web shells on publicly accessible servers

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Credential Access
Defense Evasion
Collection
Command and Control
Exfiltration
Impact
Lateral Movement

ATT&CK Techniques

T1037
T1557
T1583
T1613
T1123
T1543
T1547
T1119
T1115
T1071
T1555
T1659
T1010
T1560
T1185
T1580
T1217
T1092
T1595
T1548
T1087
T1059
T1020
T1609
T1584
T1612
T1586
T1619
T1554
T1098
T1110
T1531
T1671
T1197
T1650
T1651
T1134
T1136
T1526
T1538
T1190
T1041
T1566.001
T1059.001
T1047
T1053.005
T1078
T1485
T1486
T1059.007
T1068
T1003
T1055

Software / Tooling

GOREVERSE
ShadowPad
DarkGate
BrockenDoor
Remcos
Babuk
SpearPress_HORDE
SpearPress_MDAEMON
SpearPress_ROUNDCUBE
SpearPress_ZIMBRA
Elise
KrustyLoader
FRP
Auto-Color Linux backdoor
Havoc
HanifNet
HXLibrary
NeoExpressRAT
MeshCentral Agent
SystemBC
plink
Ngrok
Mimikatz
Syncro
PDQ
Horus Agent
Mythic

Campaigns & Victims

PurpleHaze operates through a modular, supply‑chain‑friendly framework that allows rapid pivots between espionage and money‑making operations. Notable campaigns include ShadowPad infiltration via Ivanti CVEs, Babuk ransomware spikes targeting Russian government agencies, Sednit/SpyPress JavaScript chains harvesting email data from Horde, MDaemon, and Zimbra users, and Lemon Sandstorm’s long‑running intrusions into Middle Eastern critical infrastructure through biotime CVE exploitation and WebDAV-based delivery of the Horus agent. The actor also collaborates with MuddyWater to broker access for other Iran‑aligned groups via RMM installers (Syncro, PDQ). Campaigns span the last decade, often exhibiting a pattern of initial reconnaissance on public cloud infrastructures, followed by lateral movement through remote services, and culminating in data exfiltration or ransomware deployment.

IOC Patterns

  • IP addresses
  • Domain names
  • File hashes/names
  • CVE identifiers
  • YARA rule strings
  • Spearphishing attachment patterns
  • Fake domain indicators
  • Backdoor installation signatures (e.g., GOREVERSE, DarkGate)
  • Data deletion via SDelete indicators
  • Scheduled‑task persistence entries
  • Web shell URLs on public servers

Recommended Actions

  • Immediately patch all known CVEs affecting Ivanti Cloud Services Appliance, Biotime, MDaemon, Zimbra, and Office XSS vulnerabilities.
  • Deploy endpoint detection & response (EDR) solutions with signature rules for GOREVERSE, ShadowPad, DarkGate, BrockenDoor, Remcos, Havoc, HanifNet, NeoExpressRAT, and MeshCentral Agent.
  • Block or quarantine spoofed domains that mimic legitimate organizations in DNS and web traffic.
  • Enforce Multi‑Factor Authentication across all administrative interfaces, remote services (RDP, SSH, VPN), and SaaS applications like Microsoft 365.
  • Monitor for and neutralize scheduled‑task persistence, process injection activity, and usage of PowerShell or WMI for execution.
  • Implement monitoring for SDelete or other backup‑erasure utilities to detect data wiping incidents.
  • Regularly update threat intelligence feeds to block known malicious IP addresses, domain names, and file hashes associated with PurpleHaze’s tool kit.
  • Restrict installation and use of remote monitoring/management (RMM) software such as Syncro and PDQ to authorized users only.
  • Apply continuous vulnerability scanning and patch management across all endpoints, cloud, and container environments.
  • Conduct periodic penetration tests focused on publicly exposed CVEs used by PurpleHaze.
  • Block web shells from public servers through server hardening policies and runtime monitoring.

Suggested Tags

PurpleHaze
ShadowPad
GOREVERSE
Black Owl (BO Team)
Sednit
APT28
Fancy Bear
Sofacy
DarkGate
BrockenDoor
Remcos
Babuk
Elise
SpearPress
KrustyLoader
Fast Reverse Proxy
Auto-Color Linux backdoor
PowerShell
WMI
SDelete
RDP
SSH
VPN
Phishing
XSS
CVE exploitation
Data Destruction
Backdoors
Iran-state-sponsored
Lemon Sandstorm
Stealth Falcon
MuddyWater
WebDAV exploitation
Credential dumping
Microsoft365 credential theft
Middle East CNI

Confidence Assessment

The technical profile of PurpleHaze is supported by multiple independent sources detailing its use of CVE exploitation, backdoor deployment, and ransomware activity. However, attribution to a single Chinese state‑aligned group remains partially inferred due to overlapping aliases (e.g., APT28, Fancy Bear) that have historically been linked to other operations. Information gaps include precise operational timelines, definitive evidence linking PurpleHaze’s exploits to specific incidents, and confirmation of its financial motives versus pure espionage. Overall confidence in the TTP inventory is high, whereas attribution certainty is moderate.

ATT&CK Techniques

Reconnaissance
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 3 Domain 12 IPv4 Address 5

References

  1. ics-cert.kaspersky.com — Cited by web research for: APT28
  2. www.sentinelone.com — Cited by web research for: UNC5174 by Mandiant
  3. www.sentinelone.com — Cited by web research for: other various outdated aliases
  4. attack.mitre.org — Cited by web research for: services
  5. apt.etda.or.th — Cited by web research for: Cobalt Strike
  6. attack.mitre.org — Cited by web research for: Process Hollowing
  7. https://malpedia.caad.fkie.fraunhofer.de/actor/purplehaze — Cited by AI analysis.

Intel Summary

53

Techniques

68

Tools

0

Campaigns

39

IOCs

0

Observed Data

13

Tactics

Tags

Ransomware
APT
Critical Infrastructure
Supply Chain Attack
Backdoor / C2
Government Targeting
Espionage
China-nexus
PurpleHaze
ShadowPad
GOREVERSE
Black Owl (BO Team)
Sednit
APT28
Fancy Bear
Sofacy
DarkGate
BrockenDoor
Remcos
Babuk
Elise
SpearPress
KrustyLoader
Fast Reverse Proxy
Auto-Color Linux backdoor
PowerShell
WMI
SDelete
RDP
SSH
VPN
Phishing
XSS
CVE exploitation
Data Destruction
Backdoors
Iran-state-sponsored
Lemon Sandstorm
Stealth Falcon
MuddyWater
WebDAV exploitation
Credential dumping
Microsoft365 credential theft
Middle East CNI

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.