Muddled Libra’s Evolution to the Cloud
ID: 16b71f9c-77ea-5542-9580-a9e66f00df1e
STIX ID: report--16b71f9c-77ea-5542-9580-a9e66f00df1e
Feed Name: Palo Alto Networks Unit 42
## Executive Summary Unit 42 describes the evolution of the Muddled Libra threat actor toward targeting SaaS and cloud service provider (CSP) environments: attackers use help-desk social engineering to compromise identity portals (e.g., Okta), escalate privileges via identity provider abuse, discover credentials and sensitive data across SaaS (SharePoint, M365) and cloud services (AWS IAM, S3, Secrets Manager; Azure storage and resource groups), then leverage legitimate cloud features (AWS DataSync/AWS Transfer, Azure VM snapshots and newly created VMs) to stage and exfiltrate data; the report maps these activities to MITRE ATT&CK techniques and provides detection and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
