{"id":6381,"date":"2025-08-23T10:03:36","date_gmt":"2025-08-23T10:03:36","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/08\/23\/chinese-murky-panda-attacking-government-and-professional-services-entities\/"},"modified":"2025-08-23T10:03:36","modified_gmt":"2025-08-23T10:03:36","slug":"chinese-murky-panda-attacking-government-and-professional-services-entities","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/08\/23\/chinese-murky-panda-attacking-government-and-professional-services-entities\/","title":{"rendered":"Chinese MURKY PANDA Attacking Government and Professional Services Entities"},"content":{"rendered":"<p>    Chinese MURKY PANDA Attacking Government and Professional Services Entities<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated China-nexus threat actor designated MURKY PANDA has emerged as a significant cybersecurity concern, conducting extensive cyberespionage operations against government, technology, academic, legal, and professional services entities across North America since late 2024.<\/p>\n<p>This advanced persistent threat group demonstrates exceptional capabilities in cloud environment exploitation and trusted-relationship compromises, marking a concerning evolution in state-sponsored cyber activities.<\/p>\n<p>The adversary has established itself as a formidable force through its ability to rapidly weaponize both n-day and zero-day vulnerabilities, frequently achieving initial access by exploiting internet-facing appliances.<\/p>\n<p>MURKY PANDA\u2019s operations are characterized by their focus on intelligence collection objectives, with documented cases of email exfiltration and sensitive document theft from high-profile targets.<\/p>\n<p>CrowdStrike researchers <a href=\"https:\/\/www.crowdstrike.com\/en-us\/blog\/murky-panda-trusted-relationship-threat-in-cloud\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> MURKY PANDA\u2019s activity as particularly notable for its cloud-conscious approach and advanced operational security measures.<\/p>\n<p>The threat group\u2019s sophisticated tradecraft includes modifying timestamps and systematically deleting indicators of compromise to evade detection and complicate attribution efforts.<\/p>\n<p>Their operations align with broader China-nexus targeted intrusion activities tracked by industry sources as Silk Typhoon.<\/p>\n<p>The group\u2019s arsenal includes deployment of <a href=\"https:\/\/cybersecuritynews.com\/hackers-attacking-iis-servers-with-new-web-shell-script\/\" target=\"_blank\" rel=\"noreferrer noopener\">web shells<\/a> such as Neo-reGeorg, commonly utilized by Chinese adversaries, and access to a low-prevalence custom malware family designated CloudedHope.<\/p>\n<p>Additionally, MURKY PANDA has demonstrated proficiency in leveraging compromised small office\/home office devices as operational infrastructure, mirroring tactics employed by other Chinese threat actors like VANGUARD PANDA.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-trusted-relationship-cloud-exploitation-techniques\"><strong>Trusted-Relationship Cloud Exploitation Techniques<\/strong><\/h2>\n<p>MURKY PANDA\u2019s most distinctive capability lies in conducting trusted-relationship compromises within cloud environments, representing a relatively rare and undermonitored attack vector.<\/p>\n<p>The group has successfully exploited <a href=\"https:\/\/cybersecuritynews.com\/zero-day-vulnerability-wps-office\/\" target=\"_blank\" rel=\"noreferrer noopener\">zero-day vulnerabilities<\/a> to compromise software-as-a-service providers, subsequently leveraging their access to move laterally to downstream customers.<\/p>\n<p>In documented cases, the adversary obtained application registration secrets from compromised SaaS providers using Entra ID for customer access management.<\/p>\n<p>By authenticating as service principals, MURKY PANDA gained unauthorized access to downstream customer environments, enabling email access and data exfiltration.<\/p>\n<p>This sophisticated technique demonstrates their deep understanding of <a href=\"https:\/\/cybersecuritynews.com\/best-cloud-vpn\/\" target=\"_blank\" rel=\"noreferrer noopener\">cloud architecture<\/a> and identity management systems.<\/p>\n<p>The threat actor has also targeted Microsoft cloud solution providers, exploiting delegated administrative privileges to achieve Global Administrator access across multiple downstream customer tenants, establishing persistent backdoors through newly created user accounts and modified service principal configurations.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong><code>Boost\u00a0your\u00a0SOC and help your team protect your business with free top-notch threat intelligence:\u00a0<a href=\"https:\/\/intelligence.any.run\/plans\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=alert_fatigue&amp;utm_content=lookup_plan&amp;utm_term=120825\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Request TI Lookup Premium Trial<\/a>.<\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/chinese-murky-panda-attacking-government\/\">Chinese MURKY PANDA Attacking Government and Professional Services Entities<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/chinese-murky-panda-attacking-government\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Chinese MURKY PANDA Attacking Government and Professional Services Entities A sophisticated China-nexus threat actor designated MURKY PANDA has emerged as a significant cybersecurity concern, conducting extensive cyberespionage operations against government, technology, academic, legal, and professional services entities across North America since late 2024. This advanced persistent threat group demonstrates exceptional capabilities in cloud environment exploitation [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-6381","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6381"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6381"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6381\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6381"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6381"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6381"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}