Unit 42 analyzed a rogue VM created by Muddled Libra (Scattered Spider) during a September 2025 incident. The cybercrime group gained unauthorized VMware vSphere access, created a VM to avoid endpoint detection, and used it as a beachhead for reconnaissance and data theft. Attackers downloaded stolen certificates, established

11m read time From unit42.paloaltonetworks.com
Post cover image
Table of contents
Executive SummaryWho Is Muddled Libra?Background on the Attack ChainA Peek Into Muddled Libra TacticsConclusionIndicators of CompromiseAdditional Resources

Sort: