China-linked Murky Panda targets and moves laterally through cloud services
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-3519 | Unauthenticated RCE in Citrix NetScaler ADC and NetScaler Gateway CVE-2023-3519 is a critical (CVSS 9.8) unauthenticated remote code execution flaw caused by improper code-injection handling (CWE-94) in Citrix NetScaler ADC and NetScaler Gateway. A remote attacker with no credentials can trigger it by sending crafted requests to an appliance configured as a Gateway (VPN/ICA proxy/RDP proxy) or AAA authentication virtual server, gaining arbitrary code execution on the appliance. Exploitation typically yields a foothold behind the VPN edge — access to internal networks, credential theft, and follow-on activity such as espionage or ransomware deployment. Any organization running unpatched NetScaler ADC/Gateway appliances, especially internet-facing remote-access endpoints, is affected; NetScaler is one of the most widely deployed enterprise VPN/ADC platforms. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-07-19 with known ransomware use, EPSS estimates a 99.7% exploitation probability, and researchers have linked activity to China-nexus espionage (Silk Typhoon) and ransomware operations. Do: Immediately upgrade internet-facing NetScaler ADC/Gateway appliances to the fixed builds in Citrix's advisory (14.1-8.50+, 13.1-49.13+, 13.0-82.45+, 12.1-55.300+, including FIPS/NDcPP equivalents) — per CISA KEV, apply these mitigations or discontinue use if patching is unavailable. Confirm whether each appliance is configured as a Gateway or AAA virtual server (only those are affected), and hunt for compromise — unexpected configuration changes, unfamiliar accounts, webshells, or anomalous VPN sessions — rotating credentials on any suspected compromise. | 9.8 | 100% | KEV ransomware PoC |
| largetens of thousands of internet-exposed NetScaler Gateway/ADC appliances (order 10k-100k at disclosure), serving hundreds of thousands to millions of downstream… | |
| CVE-2025-3928 | Actively Exploited Authenticated Webshell Flaw in Commvault Web Server CVE-2025-3928 is an unspecified vulnerability in the Commvault Web Server, the web administration component of Commvault's data protection platform, which can be exploited over the network by a remote attacker who holds valid (low-privilege) authenticated access. According to the Commvault advisory, attackers use the flaw to create and execute webshells on the web server, and the CVSS 4.0 score of 8.7 (High) reflects high impact to the confidentiality, integrity, and availability of the vulnerable web server component. It affects Commvault Web Server on both Windows and Linux across the supported release streams, with fixes delivered in 11.36.46, 11.32.89, 11.28.141, and 11.20.217. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-04-28, and Commvault has confirmed that hackers exploited it in the wild as a zero-day, with related reporting noting heightened Silk Typhoon (Chinese nation-state) attack activity. No public proof-of-concept is known, but the confirmed real-world zero-day exploitation makes patching urgent. Do: Upgrade the Commvault Web Server to 11.36.46, 11.32.89, 11.28.141, or 11.20.217, matching your current release stream, on both Windows and Linux platforms. Because the flaw was exploited as a zero-day, hunt for attacker-created webshells and unexpected accounts, scripts, or scheduled tasks on Commvault web server hosts, review authentication logs for suspicious logins, and restrict the Commvault web interface to trusted networks. Federal agencies must apply vendor mitigations per CISA instructions or follow BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable. | 8.7 | 2% | KEV |
| large≈ tens of thousands of enterprise deployments worldwide (one Web Server per Commvault environment); internet-exposed instances likely in the thousands |
Full article568 words · extracted from helpnetsecurity.com · click to collapse
In its recently released 2025 Threat Hunting Report, Crowdstrike pointed out an interesting trend: a 136% surge in cloud intrusions. A good chunk of this surge is due to “China-nexus adversaries”, Murky Panda (aka Silk Typhoon) among them.
Murky Panda’s modus operandi
The group has been active since at least 2023, and is primarily focused on breaching government, technology, academia, legal, and professional services entities in North America and stealing sensitive information from them.
The group is known for:
- Leveraging n-day and zero-day vulnerabilities in internet-facing appliances for initial access (e.g., CVE-2023-3519, affecting Citrix NetScaler ADC and Gateway)
- Deploying webshells (such as Neo-reGeorg) on compromised systems
- Using CloudedHope, custom Linux malware with remote access functionality
- Using compromised SOHO devices geolocated in the countries of the targets as final exit nodes, making attacks appear to originate locally
But, crucially, they also have a penchant for compromising cloud environments and using the trusted relationships within/between them to reach their intended victims.
Hopping through the cloud(s)
“In at least two cases analyzed by CrowdStrike, Murky Panda exploited zero-day vulnerabilities to achieve initial access to software-as-a-service (SaaS) providers’ cloud environments. Following the compromise, [the group] determined the compromised SaaS cloud environments’ logic, enabling them to leverage their access to that software to move laterally to downstream customers,” Crowdstrike researchers noted.
“At least one SaaS provider victim was using Entra ID to manage its SaaS application’s access to its downstream customers’ data. In this intrusion, Murky Panda almost certainly obtained access to the SaaS provider’s application registration secret, which the adversary then leveraged to authenticate as the service principals of that application and log into downstream customers’ environments. Next, leveraging their control over those service principals, Murky Panda accessed emails at the downstream customers.”
The researchers didn’t name the provider, though their description seems to fit that of the February 2025 breach of Commvault’s Microsoft Azure cloud environment and, through it, the M365 environments of their customers.
In another intrusion, Murky Panda compromised a Microsoft cloud solution provider that had cross-tenant access to a downstream customer via delegated administrative privileges (DAP).
The group used this access and the Global Administrator privileges and a compromised high-privileged user account to create a new user in a downstream victim’s tenant and add this user to several preexisting groups.
“One of those preexisting groups granted the backdoor user Application Administrator privileges, allowing Murky Panda to add secrets to preexisting service principals. With control over those newly added secrets, [the threat actor] successfully authenticated as those service principals, thereby escalating their privileges to those of the backdoored service principals.”
With those privileges, the group was able to read emails and add secrets to application registrations and service principals (for added persistence).
“Murky Panda is currently one of a few tracked adversaries that conduct trusted-relationship compromises in the cloud. Due to the activity’s rarity, this initial access vector to a victim’s cloud environment remains relatively undermonitored compared to more prominent initial access vectors such as valid cloud accounts and exploiting public-facing applications,” Crowdstrike researchers noted, and shared defense recommendations for organizations that rely heavily on cloud environments.
UPDATE (August 23, 2025, 01:10 a.m. ET):
This article has been updated to remove the reference to CVE-2025-3928 being exploited by the group, following CrowdStrike’s retraction of that claim.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/08/22/china-linked-murky-panda-targets-and-moves-laterally-through-cloud-services/