Unit 42 analyzed a rogue VM created by Muddled Libra (Scattered Spider) during a September 2025 incident. The cybercrime group gained unauthorized VMware vSphere access, created a VM to avoid endpoint detection, and used it as a beachhead for reconnaissance and data theft. Attackers downloaded stolen certificates, established
•11m read time• From unit42.paloaltonetworks.com
Table of contents
Executive SummaryWho Is Muddled Libra?Background on the Attack ChainA Peek Into Muddled Libra TacticsConclusionIndicators of CompromiseAdditional ResourcesSort: