Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Muddled Libra Exploits VMware vSphere in Cyber Attack

Muddled Libra Exploits VMware vSphere in Cyber Attack

Posted on February 12, 2026 By CWS

In a revealing cybersecurity incident from September 2025, investigators uncovered a rogue virtual machine (VM) operating within a VMware vSphere environment. This discovery was closely linked to the notorious cyber group Muddled Libra, also known as Scattered Spider and UNC3944. The group’s tactics involved using the VM as a covert staging host, facilitating network reconnaissance, tool deployment, and eventual data exfiltration.

Intrusion Tactics and Techniques

Muddled Libra is known for its adept social engineering methods, including techniques like smishing and vishing, to impersonate employees. This strategy often coerces help desks into resetting passwords or bypassing multi-factor authentication. Rather than relying heavily on malware, this group prefers to exploit legitimate administrative tools and the victim’s infrastructure to mask their presence.

According to Palo Alto Networks, attackers breached the vSphere system mere hours after initial access. They created a new VM titled “New Virtual Machine,” signifying the start of their infiltration. The attackers then obtained stolen certificates to forge authentication tickets, extending their control over the network.

Exploitation of Network Resources

The cyber operatives powered down virtualized domain controllers, accessing and copying critical files such as NTDS.dit and SYSTEM onto the rogue VM. This maneuver was part of their broader strategy to gather directory information using ADRecon and investigate service principal names. Their reach extended to the victim’s Snowflake environment, and they attempted to extract mailbox data off-network using file-sharing services and S3 Browser.

To maintain persistence, the attackers established a secure shell (SSH) tunnel using Chisel, a tool delivered via a ZIP file named goon.zip from an AWS S3 bucket under their control. Network logs indicated continuous traffic to an attacker-controlled address over TCP 443 for approximately 15 hours, mimicking standard HTTPS traffic.

Preventive Measures and Recommendations

Security experts recommend enhancing identity controls and enforcing the principle of least privilege for vSphere and administrative accounts to mitigate risks. Monitoring for suspicious VM creations, unexpected domain controller shutdowns, and unusual VMDK mounts is crucial. Additionally, vigilance is required for detecting unusual use of common tools and anomalous outbound traffic on port 443 from new systems.

By implementing these measures, organizations can better counteract the living-off-the-land tactics of cyber groups like Muddled Libra before they result in widespread lateral movement and severe data breaches.

Stay updated with the latest in cybersecurity by following us on Google News, LinkedIn, and X. Set CSN as your preferred source on Google for instant updates.

Cyber Security News Tags:Chisel tunnel, cloud services, cyber attack, Cybersecurity, data breach, identity systems, Muddled Libra, Palo Alto Networks, social engineering, virtual machine, VMware vSphere

Post navigation

Previous Post: Feiniu NAS Devices Targeted in Major Botnet Attack
Next Post: CISA Highlights Notepad++ Vulnerability Amid Active Exploits

Related Posts

Breaking Message Queuing (MSMQ) Functionality Affects IIS Sites Breaking Message Queuing (MSMQ) Functionality Affects IIS Sites Cyber Security News
Chinese UNC6384 Hackers Leverages Valid Code Signing Certificates to Evade Detection Chinese UNC6384 Hackers Leverages Valid Code Signing Certificates to Evade Detection Cyber Security News
Ransomware Actors Exploit Unpatched SimpleHelp RMM to Compromise Billing Software Provider Ransomware Actors Exploit Unpatched SimpleHelp RMM to Compromise Billing Software Provider Cyber Security News
Here’s How to Solve It  Here’s How to Solve It  Cyber Security News
SideWinder APT Hackers Attacking Indian Entities by Masquerading as the Income Tax Department of India SideWinder APT Hackers Attacking Indian Entities by Masquerading as the Income Tax Department of India Cyber Security News
PamDOORa Backdoor Threatens Linux by Stealing SSH Credentials PamDOORa Backdoor Threatens Linux by Stealing SSH Credentials Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Adobe Addresses 123 Security Flaws in Major Update
  • Meta Enhances AI with External Business Data
  • MagicAd Malware Bypasses Android Restrictions with Ads
  • Anthropic Unveils Claude Fable 5: Secure Mythos-Class AI
  • Hades Attack Targets PyPI: 19 Packages Compromised

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Adobe Addresses 123 Security Flaws in Major Update
  • Meta Enhances AI with External Business Data
  • MagicAd Malware Bypasses Android Restrictions with Ads
  • Anthropic Unveils Claude Fable 5: Secure Mythos-Class AI
  • Hades Attack Targets PyPI: 19 Packages Compromised

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark