216.73.216.6

A Peek Into Muddled Libra's Operational Playbook

· Published 11/02/2026 03:22 · Modified 11/02/2026 11:05

Export JSON

Essential information

Published
11/02/2026 03:22
Modified
11/02/2026 11:05
Tags
2026-02-11 muddled libra vmware
Related entities
4 observables, 1 intrusion sets (apt), 25 techniques (mitre), 2 others

Description

Unit 42 discovered a rogue virtual machine used by the cybercrime group during an incident response investigation. The VM provided insights into the group's operational methods, including reconnaissance, tool downloads, persistence establishment, certificate theft, and interactions with the target's infrastructure. created the VM after gaining unauthorized access to the target's vSphere environment. The group's tactics involve minimal malware use, preferring to leverage the target's assets. Their attack chain included creating a VM, downloading tools, establishing C2, using stolen certificates, and attempting data exfiltration. The article details the group's activities, tools used, and troubleshooting efforts during the attack.

External references