Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Muddled Libra Exploits VMware vSphere in Cyber Attack

Muddled Libra Exploits VMware vSphere in Cyber Attack

Posted on February 12, 2026 By CWS

In a revealing cybersecurity incident from September 2025, investigators uncovered a rogue virtual machine (VM) operating within a VMware vSphere environment. This discovery was closely linked to the notorious cyber group Muddled Libra, also known as Scattered Spider and UNC3944. The group’s tactics involved using the VM as a covert staging host, facilitating network reconnaissance, tool deployment, and eventual data exfiltration.

Intrusion Tactics and Techniques

Muddled Libra is known for its adept social engineering methods, including techniques like smishing and vishing, to impersonate employees. This strategy often coerces help desks into resetting passwords or bypassing multi-factor authentication. Rather than relying heavily on malware, this group prefers to exploit legitimate administrative tools and the victim’s infrastructure to mask their presence.

According to Palo Alto Networks, attackers breached the vSphere system mere hours after initial access. They created a new VM titled “New Virtual Machine,” signifying the start of their infiltration. The attackers then obtained stolen certificates to forge authentication tickets, extending their control over the network.

Exploitation of Network Resources

The cyber operatives powered down virtualized domain controllers, accessing and copying critical files such as NTDS.dit and SYSTEM onto the rogue VM. This maneuver was part of their broader strategy to gather directory information using ADRecon and investigate service principal names. Their reach extended to the victim’s Snowflake environment, and they attempted to extract mailbox data off-network using file-sharing services and S3 Browser.

To maintain persistence, the attackers established a secure shell (SSH) tunnel using Chisel, a tool delivered via a ZIP file named goon.zip from an AWS S3 bucket under their control. Network logs indicated continuous traffic to an attacker-controlled address over TCP 443 for approximately 15 hours, mimicking standard HTTPS traffic.

Preventive Measures and Recommendations

Security experts recommend enhancing identity controls and enforcing the principle of least privilege for vSphere and administrative accounts to mitigate risks. Monitoring for suspicious VM creations, unexpected domain controller shutdowns, and unusual VMDK mounts is crucial. Additionally, vigilance is required for detecting unusual use of common tools and anomalous outbound traffic on port 443 from new systems.

By implementing these measures, organizations can better counteract the living-off-the-land tactics of cyber groups like Muddled Libra before they result in widespread lateral movement and severe data breaches.

Stay updated with the latest in cybersecurity by following us on Google News, LinkedIn, and X. Set CSN as your preferred source on Google for instant updates.

Cyber Security News Tags:Chisel tunnel, cloud services, cyber attack, Cybersecurity, data breach, identity systems, Muddled Libra, Palo Alto Networks, social engineering, virtual machine, VMware vSphere

Post navigation

Previous Post: Feiniu NAS Devices Targeted in Major Botnet Attack
Next Post: CISA Highlights Notepad++ Vulnerability Amid Active Exploits

Related Posts

Threat Intelligence That Powers Best SOCs Worldwide Is Now Free   Threat Intelligence That Powers Best SOCs Worldwide Is Now Free   Cyber Security News
Tenda N300 Vulnerabilities Let Attacker to Execute Arbitrary Commands as Root User Tenda N300 Vulnerabilities Let Attacker to Execute Arbitrary Commands as Root User Cyber Security News
Best Network Security Providers for Healthcare Best Network Security Providers for Healthcare Cyber Security News
New Tool Released to Detect Cisco Secure Email Gateway 0-Day Vulnerability Exploited in the Wild New Tool Released to Detect Cisco Secure Email Gateway 0-Day Vulnerability Exploited in the Wild Cyber Security News
Quantum Threats Preparing Your Encryption Strategy Quantum Threats Preparing Your Encryption Strategy Cyber Security News
Xerox FreeFlow Core Vulnerability Let Remote Attackers Execute Malicious Code Xerox FreeFlow Core Vulnerability Let Remote Attackers Execute Malicious Code Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • FBI Verifies Email Breach as US Offers Reward for Hackers
  • Critical F5 BIG-IP Vulnerability Now Actively Exploited
  • China-Linked Cyber Threats Target Southeast Asian Government
  • AI-Powered VoidLink Malware Framework Poses New Cyber Threat
  • Top Log Monitoring Tools to Watch in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • FBI Verifies Email Breach as US Offers Reward for Hackers
  • Critical F5 BIG-IP Vulnerability Now Actively Exploited
  • China-Linked Cyber Threats Target Southeast Asian Government
  • AI-Powered VoidLink Malware Framework Poses New Cyber Threat
  • Top Log Monitoring Tools to Watch in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark