Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Muddled Libra Exploits VMware vSphere in Cyber Attack

Muddled Libra Exploits VMware vSphere in Cyber Attack

Posted on February 12, 2026 By CWS

In a revealing cybersecurity incident from September 2025, investigators uncovered a rogue virtual machine (VM) operating within a VMware vSphere environment. This discovery was closely linked to the notorious cyber group Muddled Libra, also known as Scattered Spider and UNC3944. The group’s tactics involved using the VM as a covert staging host, facilitating network reconnaissance, tool deployment, and eventual data exfiltration.

Intrusion Tactics and Techniques

Muddled Libra is known for its adept social engineering methods, including techniques like smishing and vishing, to impersonate employees. This strategy often coerces help desks into resetting passwords or bypassing multi-factor authentication. Rather than relying heavily on malware, this group prefers to exploit legitimate administrative tools and the victim’s infrastructure to mask their presence.

According to Palo Alto Networks, attackers breached the vSphere system mere hours after initial access. They created a new VM titled “New Virtual Machine,” signifying the start of their infiltration. The attackers then obtained stolen certificates to forge authentication tickets, extending their control over the network.

Exploitation of Network Resources

The cyber operatives powered down virtualized domain controllers, accessing and copying critical files such as NTDS.dit and SYSTEM onto the rogue VM. This maneuver was part of their broader strategy to gather directory information using ADRecon and investigate service principal names. Their reach extended to the victim’s Snowflake environment, and they attempted to extract mailbox data off-network using file-sharing services and S3 Browser.

To maintain persistence, the attackers established a secure shell (SSH) tunnel using Chisel, a tool delivered via a ZIP file named goon.zip from an AWS S3 bucket under their control. Network logs indicated continuous traffic to an attacker-controlled address over TCP 443 for approximately 15 hours, mimicking standard HTTPS traffic.

Preventive Measures and Recommendations

Security experts recommend enhancing identity controls and enforcing the principle of least privilege for vSphere and administrative accounts to mitigate risks. Monitoring for suspicious VM creations, unexpected domain controller shutdowns, and unusual VMDK mounts is crucial. Additionally, vigilance is required for detecting unusual use of common tools and anomalous outbound traffic on port 443 from new systems.

By implementing these measures, organizations can better counteract the living-off-the-land tactics of cyber groups like Muddled Libra before they result in widespread lateral movement and severe data breaches.

Stay updated with the latest in cybersecurity by following us on Google News, LinkedIn, and X. Set CSN as your preferred source on Google for instant updates.

Cyber Security News Tags:Chisel tunnel, cloud services, cyber attack, Cybersecurity, data breach, identity systems, Muddled Libra, Palo Alto Networks, social engineering, virtual machine, VMware vSphere

Post navigation

Previous Post: Feiniu NAS Devices Targeted in Major Botnet Attack

Related Posts

Hackers Actively Compromising Databases Using Legitimate Commands Hackers Actively Compromising Databases Using Legitimate Commands Cyber Security News
PhantomRaven Attack Involves 126 Malicious npm Packages with Over 86,000 Downloads Hiding Malicious Code PhantomRaven Attack Involves 126 Malicious npm Packages with Over 86,000 Downloads Hiding Malicious Code Cyber Security News
Cisco Unified Contact Center Express Vulnerabilities Enables Remote Code Execution Attacks Cisco Unified Contact Center Express Vulnerabilities Enables Remote Code Execution Attacks Cyber Security News
New Active Directory Lateral Movement Techniques that Bypasses Authentication and Exfiltrate Data New Active Directory Lateral Movement Techniques that Bypasses Authentication and Exfiltrate Data Cyber Security News
Critical ASP.NET Vulnerability Allows Attacker To Bypass Security Feature Remotely Critical ASP.NET Vulnerability Allows Attacker To Bypass Security Feature Remotely Cyber Security News
Developers Expose Passwords and API Keys via Online Tools like JSONFormatter Developers Expose Passwords and API Keys via Online Tools like JSONFormatter Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News