Palo Alto Networks Unit 42 reported that during a September 2025 incident response engagement, investigators identified a rogue virtual machine created inside a victim’s VMware vSphere environment and attributed the activity with high confidence to Muddled Libra (aka Scattered Spider, UNC3944). After gaining unauthorized access to vSphere, the actor used the VM as a low-noise staging point to conduct reconnaissance, download tools, and establish persistence via a C2 channel, consistent with the group’s pattern of blending into victim infrastructure and relying on legitimate administrative capabilities rather than heavy custom malware.
The intrusion chain described includes rapid post-access interaction with vSphere (roughly hours after initial access), creation of a new VM, and subsequent use of stolen certificates to expand control (including ticket-forging activity). The actor then targeted identity infrastructure by powering down virtualized domain controllers, mounting their VMDKs, and copying NTDS.dit and SYSTEM to the rogue VM, followed by directory discovery (e.g., ADRecon and review of service principal names). The reporting also notes interaction with the victim’s Snowflake environment and attempted data movement (including mailbox/PST-related activity), plus persistence using an SSH tunnel via Chisel delivered as a ZIP (e.g., goon.zip) from attacker-controlled infrastructure (including AWS S3) and outbound communications over TCP 443.

Get the actors, campaigns, and ATT&CK mapping behind it.
7 events from the most recent confirmed update back to the earliest known activity.
On 2026-02-10, Palo Alto Networks Unit 42 publicly detailed the September 2025 incident and attributed the activity with high confidence to Muddled Libra, also known as Scattered Spider or UNC3944. The report highlighted the group's use of living-off-the-land techniques, identity abuse, and recommendations for stronger identity controls and monitoring.
After about 15 hours of observed attacker activity, the victim's security team cut off the attackers' access and ended the intrusion. Microsoft Defender on the rogue VM had reportedly detected several of the tools used during the operation.
During the same intrusion, the attackers interacted with the victim's Snowflake environment and attempted to exfiltrate data through multiple file-sharing services. They also tried uploading an Outlook PST file to an attacker-controlled AWS S3 bucket using S3 Browser.
From the rogue VM, the group set up an SSH tunnel with Chisel for persistence and carried out extensive enumeration using tools such as ADRecon and ADExplorer. They also used legitimate administrative utilities including RDP and PsExec to blend in while moving through the environment.
Using vSphere access, the attackers powered down domain controllers, mounted their VMDKs, and copied NTDS.dit and SYSTEM hive files to the rogue VM. This enabled extraction and decryption of Active Directory credential material and helped expand their control.
Roughly two hours after initial access in the September 2025 incident, the attackers entered the victim's VMware vSphere environment and created a rogue virtual machine named "New Virtual Machine." The VM was used as an internal beachhead for reconnaissance, tool staging, persistence, and lateral movement.
In September 2025, Muddled Libra obtained unauthorized access to the victim environment by targeting help desk or call center processes, according to Unit 42's assessment. The intrusion relied on identity abuse and social engineering rather than a novel exploit.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecybersecuritynews.com
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.