logo

Muddled Libra’s Evolution to the Cloud

ID: 16b71f9c-77ea-5542-9580-a9e66f00df1e

STIX ID: report--16b71f9c-77ea-5542-9580-a9e66f00df1e

Feed Name: Palo Alto Networks Unit 42

Threat Score
80/100

Date Published: 2024-04-09

Date Updated: 2026-04-28

Author: Margaret Zimmermann

...
...

## Executive Summary Unit 42 describes the evolution of the Muddled Libra threat actor toward targeting SaaS and cloud service provider (CSP) environments: attackers use help-desk social engineering to compromise identity portals (e.g., Okta), escalate privileges via identity provider abuse, discover credentials and sensitive data across SaaS (SharePoint, M365) and cloud services (AWS IAM, S3, Secrets Manager; Azure storage and resource groups), then leverage legitimate cloud features (AWS DataSync/AWS Transfer, Azure VM snapshots and newly created VMs) to stage and exfiltrate data; the report maps these activities to MITRE ATT&CK techniques and provides detection and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.