logo

Silk Typhoon Attacks North American Orgs in the Cloud

ID: 90b72a57-ebb4-5702-944b-bfeedab69611

STIX ID: report--90b72a57-ebb4-5702-944b-bfeedab69611

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2025-08-22

Date Updated: 2026-05-05

Author: Nate Nelson, Contributing Writer

...
...

Silk Typhoon (also known as Hafnium/Murky Panda), a China-linked APT, has shifted to cloud and supply-chain operations where it compromises SaaS providers, service principals, and managed service provider accounts to access downstream customers' environments. The group has exploited high-severity vulnerabilities (including CVE-2023-3519) and used a Golang RAT called CloudedHope to establish persistence and exfiltrate emails and intelligence from government, technology, academic, legal, and professional services organizations across North America, highlighting risks in broad cloud trust relationships.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.