CrowdStrike reported that MURKY PANDA, a China-nexus espionage group active since at least 2023, compromised cloud trusted relationships to reach downstream customer environments in North America. The actor targeted government, technology, academic, legal, and professional services organizations, first gaining access through internet-facing appliances by rapidly exploiting n-day and zero-day vulnerabilities, then deploying tools including the Neo-reGeorg web shell and the low-prevalence Linux malware family CloudedHope.
In cloud intrusions, the group abused Microsoft Entra ID application secrets, service principals, and delegated administrative privileges after compromising SaaS providers and a Microsoft cloud solution provider. Because Entra ID applications can create tenant-specific service principals with local permissions across multiple customer tenants, the attackers were able to pivot into downstream environments, access customer email, escalate privileges, and maintain persistence. CrowdStrike said the campaign was aimed at intelligence collection and was supported by strong operational security, including timestamp tampering, log sanitization, and the use of compromised SOHO devices as exit nodes.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
CrowdStrike reported notable MURKY PANDA activity since late 2024. The actor was observed using trusted-relationship compromises in cloud environments, including SaaS providers and a Microsoft cloud solution provider, to reach downstream customer tenants.
CrowdStrike said its Services and Counter Adversary Operations teams investigated multiple MURKY PANDA intrusions since 2023, describing the actor as active since at least that year. The activity included targeting organizations in North America and exploiting internet-facing appliances such as Citrix NetScaler.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.