Get a Demo
Under Attack?
murky-panda

MURKY PANDA and the Blind Spot in Modern Cloud Security

<br />
<b>Warning</b>:  Undefined variable $photo in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
<br />
<b>Warning</b>:  Trying to access array offset on value of type null in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
Chris Lentricchia September 10, 2025

August 21, 2025 – CrowdStrike disclosed ongoing activity by MURKY PANDA, a state-aligned Chinese espionage group purpose-built for the cloud. Unlike many threat actors who adapt legacy tactics, MURKY PANDA designs operations around cloud-native infrastructure from the ground up. Their latest campaign combines a Linux malware strain, a Commvault zero-day exploit, and identity abuse in Microsoft Entra ID to achieve long-term persistence, all while evading traditional detection.

Overview

State-backed groups have targeted cloud assets for years, but MURKY PANDA marks a turning point. Their operations aren’t simply on-premise tactics lifted into the cloud, they are engineered for the unique trust models and identity fabrics of SaaS, IaaS, and hybrid environments.

Targets include government agencies, research institutions, multinational tech firms, and increasingly, law firms and professional services providers that act as custodians of sensitive data. What makes them dangerous isn’t just malware. It’s their ability to weaponize the implicit trust built into cross-tenant permissions, service principals, and delegated access.

Screenshot-2025-09-02-at-8.24.11-AM
Upwind’s Cloud Baselines go beyond traditional threat detection methods to automatically highlight suspicious or malicious network and process activities

Technical Analysis: A Campaign That Blends In

CrowdStrike’s reporting highlights how MURKY PANDA gains access and maintains stealth through three primary mechanisms:

  • Custom Linux Malware: CloudedHope
    A lightweight implant tailored for containerized cloud workloads. It avoids high-noise activities such as file system modification or privilege escalation. Instead, it hides in plain sight within process execution and network traffic, leveraging Python sockets and socat to maintain command-and-control (C2).
  • Exploitation of CVE-2025-3928 (Commvault Zero-Day)
    Used for initial access, the flaw undermines backup infrastructure itself, compromising systems specifically designed to protect critical data.
  • Identity Abuse in Microsoft Entra ID
    By manipulating Service Principals and exploiting GDAP/DAP cross-tenant relationships, MURKY PANDA achieves lateral movement across federated environments, pivoting seamlessly under the guise of legitimate credentials.

Each action is deliberate. Each blends into normal administrative behavior. And in log data, each appears indistinguishable from authorized activity.

Why Log-Based Security Fails in the Cloud

Most security teams depend on logs (API activity, audit trails, authentication events) to detect threats. But MURKY PANDA’s approach highlights why this model fails against cloud-native adversaries:

  • Valid Credentials Look Legitimate
    Service Principal abuse produces “valid” actions in logs. Nothing triggers as anomalous.
  • Low-Noise Persistence
    Reverse shells via ssh -R or socat leave little forensic residue.
  • Invisible Process-Level Activity
    Inline execution of Python socket code or outbound TLS tunnels via openssl s_client are not captured in API logs.

From a log-only perspective, everything appears normal until exfiltration occurs, at which point it’s too late.

Runtime Visibility: Seeing What Logs Miss

Catching groups like MURKY PANDA requires runtime visibility and monitoring workloads at the process, network, and command-execution level. Activity-based baselining and deviation detection expose malicious actions that logs never surface.

Had runtime visibility been applied during this campaign, defenders would have seen clear compromise signals:

  • Reverse shell creation with nc or socat
  • SSH tunneling via ssh -R
  • Inline Python socket execution for C2
  • Outbound encrypted sessions launched via openssl s_client
  • Remote code execution attempts with curl | sh
Screenshot-2025-09-02-at-8.29.54-AM
Upwind’s GenAI Threat Stories detect advanced attack patterns, connecting the dots between seemingly isolated incidents leading up to a security incident.

Each of these actions is a clear signal of compromise, but only if you’re watching the system in motion, not the logs in retrospect.

How Upwind Protects You From MURKY PANDA

MURKY PANDA’s campaign highlights a broader reality: cloud-native threats are no longer rare, they are the new baseline. With over 24,500 vulnerabilities disclosed in 2025 alone and attackers increasingly abusing cloud trust relationships instead of just CVEs, traditional log-based defenses leave organizations blind.

Screenshot-2025-09-02-at-8.32.29-AM
​​The new enhanced Upwind Threat Dashboard proves why runtime security is imperative. Against MURKY PANDA’s cloud-native attacks, only runtime visibility can cut through noise and expose real threats as they happen.

Upwind provides runtime visibility and protection to detect and stop campaigns like MURKY PANDA by enabling you to:

  • Deliver Proactive Protection
    When Upwind detects activity consistent with advanced actors like MURKY PANDA, your team receives detailed, environment-specific guidance to mitigate risks before attackers can exfiltrate data.
  • Expose Hidden Blind Spots
    Upwind automatically baselines your cloud workloads, identifying abnormal process execution and network tunneling that log-based tools miss.
  • Detect Lateral Movement in Real Time
    Using eBPF-powered runtime monitoring, Upwind surfaces abuse of Service Principals, GDAP/DAP trust relationships, and tunneling behaviors (ssh -Rsocat, inline Python sockets) the moment they occur.
  • Correlate and Prioritize Threats
    Each detection is enriched with runtime context, tying together identity abuse, malware execution, and network anomalies so your team can rapidly assess intent and take action.

Schedule a call with us today to learn more about how Upwind detects lateral movement, reverse shells, and command-level attacks, in real time, across every layer of your cloud environment.

Contents

Further Reading

The Risk Isn't What You Prompt, It's What You Built.

The Risk Isn’t What You Prompt, It’s What You Built

Key Takeaways: Agentic AI security is an architecture problem, not a policy problem. Most organizations have adopted AI agents in the form of coding assistants, autonomous workflow tools, internal chatbots connected to production systems, but without establishing the foundational security frameworks those systems require. The adoption pressure is real. Telling your engineering team to stop…
Upwind is a Visionary Leader in Frost & Sullivan report

Upwind Named a Strong Visionary Leader in Frost & Sullivan’s 2026 Cloud/Application Runtime Security Radar

We're excited to share that Frost & Sullivan has recognized Upwind as a Strong Visionary Leader in the Frost Radar™: Cloud/Application Runtime Security, 2026. This recognition highlights the company's innovation, growth, and leadership in the emerging Cloud-Native Application Detection and Response (CNADR) market. For us, the recognition is meaningful not simply because of where Upwind…
API Custom Threat Detection

Upwind brings Custom Detection Policies for APIs

Every API has a different risk profile. An internal billing endpoint and a public-facing authorization endpoint don't fail the same way. They don't get attacked the same way either. A generic ruleset can't account for that. Custom rules can, and now those rules can see sensitive data too. This new release brings two things together…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS