logo

Muddled Libra Shifts Focus to SaaS and Cloud for Extortion and Data Theft Attacks

ID: 2d2a8348-72a8-5dc8-8921-7cb3a95205c1

STIX ID: report--2d2a8348-72a8-5dc8-8921-7cb3a95205c1

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-04-15

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Muddled Libra (linked to clusters such as Scattered Spider) is actively targeting SaaS and cloud provider environments using sophisticated social engineering (phone-based helpdesk impersonation) and credential-harvesting phishing of Okta/SSO pages; they perform extensive reconnaissance to identify admin accounts and cloud credentials, then abuse legitimate CSP features (e.g., AWS DataSync/Transfer, Azure snapshots) to exfiltrate data for extortion and monetization, prompting recommendations to strengthen identity protections like hardware tokens or biometrics.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.