PurpleHaze is a threat cluster disclosed by SentinelOne in April 2025. It targeted a South Asian government supporting entity with a Windows backdoor called GoReShell, which uses functionalities from the reverse_ssh tool to establish reverse SSH connections to attacker-controlled hosts.