Rogue VM Linked to Muddled Libra in VMware vSphere Attack, Exposing Critical TTPs
ID: c675fadf-be5a-5235-9354-c58de99fa26b
STIX ID: report--c675fadf-be5a-5235-9354-c58de99fa26b
Feed Name: GBHackers
This report analyzes a September 2025 intrusion by Muddled Libra (Scattered Spider / UNC3944) in which attackers created a rogue VM inside a victim's VMware vSphere environment to act as a beachhead, steal credentials (including NTLM and Kerberos hashes and copies of NTDS.dit and SYSTEM), forge tickets, and perform lateral movement and data exfiltration from Snowflake using living‑off‑the‑land tools (Chisel, ADRecon, ADExplorer, PsExec) and cloud storage/file‑sharing services; the analysis emphasizes identity‑centric social engineering, the abuse of legitimate admin workflows, key detection points (unusual VM creation, DC shutdowns, bulk AD/database access), and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
