logo

Rogue VM Linked to Muddled Libra in VMware vSphere Attack, Exposing Critical TTPs

ID: c675fadf-be5a-5235-9354-c58de99fa26b

STIX ID: report--c675fadf-be5a-5235-9354-c58de99fa26b

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-02-12

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

This report analyzes a September 2025 intrusion by Muddled Libra (Scattered Spider / UNC3944) in which attackers created a rogue VM inside a victim's VMware vSphere environment to act as a beachhead, steal credentials (including NTLM and Kerberos hashes and copies of NTDS.dit and SYSTEM), forge tickets, and perform lateral movement and data exfiltration from Snowflake using living‑off‑the‑land tools (Chisel, ADRecon, ADExplorer, PsExec) and cloud storage/file‑sharing services; the analysis emphasizes identity‑centric social engineering, the abuse of legitimate admin workflows, key detection points (unusual VM creation, DC shutdowns, bulk AD/database access), and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.