logo

A Peek Into Muddled Libra’s Operational Playbook

ID: 209bdc27-ffbc-5bb6-a4d0-b2e3ca7c3a96

STIX ID: report--209bdc27-ffbc-5bb6-a4d0-b2e3ca7c3a96

Feed Name: Palo Alto Networks Unit 42

Threat Score
78/100

Date Published: 2026-02-10

Date Updated: 2026-04-28

Author: Justin De Luna, Noah Rincon and Cuong Dinh

...
...

Unit 42 investigated a September 2025 intrusion by Muddled Libra (Scattered Spider/UNC3944) where the adversary created a rogue VM in the victim's vSphere environment as a beachhead to harvest certificates, create SSH tunnels (Chisel), mount powered-down DC VMDKs to extract NTDS.dit and SYSTEM registry hives, run ADRecon/ADExplorer to map Active Directory, interact with Snowflake data, and attempt exfiltration via S3 and file-sharing services; the report contains detailed TTPs, forensic artifacts and IoCs to aid detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.