A Peek Into Muddled Libra’s Operational Playbook
ID: 209bdc27-ffbc-5bb6-a4d0-b2e3ca7c3a96
STIX ID: report--209bdc27-ffbc-5bb6-a4d0-b2e3ca7c3a96
Feed Name: Palo Alto Networks Unit 42
Date Published: 2026-02-10
Date Updated: 2026-04-28
Author: Justin De Luna, Noah Rincon and Cuong Dinh
Unit 42 investigated a September 2025 intrusion by Muddled Libra (Scattered Spider/UNC3944) where the adversary created a rogue VM in the victim's vSphere environment as a beachhead to harvest certificates, create SSH tunnels (Chisel), mount powered-down DC VMDKs to extract NTDS.dit and SYSTEM registry hives, run ADRecon/ADExplorer to map Active Directory, interact with Snowflake data, and attempt exfiltration via S3 and file-sharing services; the report contains detailed TTPs, forensic artifacts and IoCs to aid detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
