Trojan Horse in the Server Room: Muddled Libra’s Rogue VM Strategy Exposed
ID: d0e45087-92ba-55a8-98b6-45f30a078d8a
STIX ID: report--d0e45087-92ba-55a8-98b6-45f30a078d8a
Feed Name: securityonline.info
Unit 42 details how Muddled Libra (Scattered Spider/UNC3944) used social engineering against support staff to gain access to a victim's VMware vSphere, spin up a rogue VM as an operational base, and then rely on standard administrative utilities and living‑off‑the‑land techniques to map the network, establish C2 and persistence, and exfiltrate data (including interactions with Snowflake); the report emphasizes that the group's effectiveness stems from exploiting human trust and weak access controls and recommends defense‑in‑depth, identity protection, least‑privileged access, and detection of living‑off‑the‑land behaviors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
