Silk Typhoon Exploiting Trusted Relationships for Cloud Environments Compromise (Campaign)
ID: 6c7f06b9-4bca-5a23-8f72-74bad18e5eb6
STIX ID: report--6c7f06b9-4bca-5a23-8f72-74bad18e5eb6
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-08-24
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Silk Typhoon (Murky Panda) targets cloud environments by exploiting internet-facing appliances (notably Citrix NetScaler CVE-2023-3519) and compromising upstream SaaS/MSP providers; they abuse Entra ID application registrations and delegated administrative privileges (DAP/GDAP) to hijack service principals or Global Admin accounts, pivot into downstream customers, deploy Neo-reGeorg webshells and a Golang RAT named CloudedHope, and access sensitive data such as email.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
