Muddled Libra Shifts Focus to SaaS and Cloud for Extortion and Data Theft Attacks
ID: 2d2a8348-72a8-5dc8-8921-7cb3a95205c1
STIX ID: report--2d2a8348-72a8-5dc8-8921-7cb3a95205c1
Feed Name: The Hacker News
Muddled Libra (linked to clusters such as Scattered Spider) is actively targeting SaaS and cloud provider environments using sophisticated social engineering (phone-based helpdesk impersonation) and credential-harvesting phishing of Okta/SSO pages; they perform extensive reconnaissance to identify admin accounts and cloud credentials, then abuse legitimate CSP features (e.g., AWS DataSync/Transfer, Azure snapshots) to exfiltrate data for extortion and monetization, prompting recommendations to strengthen identity protections like hardware tokens or biometrics.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
