Also known as: Nylon Typhoon, APT28, Fancy Bear, tracked as, drug street names, for decades, UNC5174 by Mandiant, GOREVERSE, Mysterious Elephant, other various outdated aliases, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, Paper Werewolf, Rare Werewolf, Central Asia, DarkGaboon, Vengeful Wolf, Black Owl, Lifting Zmiy, Hoody Hyena, which targets Russian companies, FoxBlade, MDaemon, Zimbra, in addition to Roundcube, Lotus Blossom, Lotus Panda, February 2025, Parisite, Pioneer Kitten, UNC757, FruityArmor, Sofacy, UNK_RemoteRogue, VIXEN PANDA, Ke3Chang, Playful Dragon, Metushy, Lurid, Social Network Team, Royal APT, BRONZE PALACE, BRONZE DAVENPORT, BRONZE IDLEWOOD, NICKEL, G0004, Red Vulture, Mirage, RIVER CASTLE, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code, Rezet, Head Mare, Unicorn, LAUNDRY BEAR, Bronze Elgin
PurpleHaze combines advanced vulnerability exploitation with a broad arsenal of pre‑existing malware to achieve persistence and exfiltration objectives. The actor has repeatedly leveraged recently disclosed CVEs—particularly in Ivanti Cloud Services Appliance, Biotime, MDaemon, Zimbra, and various Office/MDaemon exploits—to gain initial foothold in target environments. Once inside, PurpleHaze deploys a suite of publicly available backdoors, including GOREVERSE (reverse SSH), ShadowPad, DarkGate, BrockenDoor, Remcos, and several custom implants such as Havoc, HanifNet, NeoExpressRAT, and MeshCentral Agent. These backdoors often reside in malicious cloud or container images to maintain persistence on cloud platforms, while the actor also uses living‑off‑the‑land (LoL) techniques—PowerShell, WMI, and scheduled tasks—to avoid detection. The group routinely exfiltrates data over application layer protocols (T1071), via public web services, and through command‑and‑control channels embedded in legitimate cloud platforms. After exfiltration it may encrypt or delete backups with SDelete to cover tracks or deploy Babuk ransomware for monetization. PurpleHaze’s operations display a sophisticated blend of cyber espionage, impact, and financial theft across multiple industry sectors.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
PurpleHaze is a highly sophisticated China‑linked threat actor that blends public CVE exploitation with readily available backdoors such as GOREVERSE and ShadowPad. The group prioritizes government, critical infrastructure, finance, and telecom targets worldwide through spearphishing, living‑off‑the‑land execution, and cloud/container persistence, routinely inserting ransomware (Babuk) to monetize exfiltration efforts. Its attacks exhibit both espionage motives and clear financial gain objectives.
Goals & Targeting
PurpleHaze's strategic objectives revolve around obtaining sensitive information from high-value targets—including governmental agencies, defense contractors, critical infrastructure operators, and major financial institutions—while simultaneously seizing financial opportunities through ransomware. The actor displays a geographic focus on countries with significant economic or geopolitical importance, spanning North America, Eurasia, the Middle East, and parts of Asia. By embedding themselves in shared supply chains and exploiting public cloud resources, PurpleHaze aims to achieve persistence, stealth, and rapid lateral movement within complex enterprise environments.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
PurpleHaze operates through a modular, supply‑chain‑friendly framework that allows rapid pivots between espionage and money‑making operations. Notable campaigns include ShadowPad infiltration via Ivanti CVEs, Babuk ransomware spikes targeting Russian government agencies, Sednit/SpyPress JavaScript chains harvesting email data from Horde, MDaemon, and Zimbra users, and Lemon Sandstorm’s long‑running intrusions into Middle Eastern critical infrastructure through biotime CVE exploitation and WebDAV-based delivery of the Horus agent. The actor also collaborates with MuddyWater to broker access for other Iran‑aligned groups via RMM installers (Syncro, PDQ). Campaigns span the last decade, often exhibiting a pattern of initial reconnaissance on public cloud infrastructures, followed by lateral movement through remote services, and culminating in data exfiltration or ransomware deployment.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The technical profile of PurpleHaze is supported by multiple independent sources detailing its use of CVE exploitation, backdoor deployment, and ransomware activity. However, attribution to a single Chinese state‑aligned group remains partially inferred due to overlapping aliases (e.g., APT28, Fancy Bear) that have historically been linked to other operations. Information gaps include precise operational timelines, definitive evidence linking PurpleHaze’s exploits to specific incidents, and confirmation of its financial motives versus pure espionage. Overall confidence in the TTP inventory is high, whereas attribution certainty is moderate.
No campaigns linked yet.
No observed data linked yet.
53
Techniques
68
Tools
0
Campaigns
39
IOCs
0
Observed Data
13
Tactics