Muddled Libra—also tracked as Scattered Spider and UNC3944—resumed intrusion activity with faster, broader operations across government, retail, insurance, and aviation organizations, relying heavily on voice-based social engineering to manipulate help desks and users into resetting credentials and MFA. Investigators reported the group often minimizes malware use, abuses legitimate tools and victim-owned assets, and can move from initial access to high privilege extremely quickly, including one case where domain administrator access was reached in about 40 minutes. Since at least April 2025, the actor has also worked with the DragonForce ransomware-as-a-service program, with incidents involving large-scale data theft followed by encryption.
Separate technical analysis tied the group to the bedevil (bdvl) Linux userland rootkit used against VMware vCenter servers, where it hides LD_PRELOAD persistence by patching dynamic linker binaries to reference a randomly generated preload path instead of /etc/ld.so.preload. The technique is designed to evade normal inspection tools and can restore the original linker path during uninstall or backdoor-triggered cleanup. Researchers said defenders can uncover the hidden preload path by tracing the first file access of dynamically linked binaries and can identify tampering through package integrity checks such as rpm -V glibc or debsums, while stronger Microsoft Entra ID Conditional Access policies can materially slow the group’s cloud-focused operations and reduce ransomware impact.

Get the infrastructure and lures behind it.
6 events from the most recent confirmed update back to the earliest known activity.
Since at least April 2025, Muddled Libra has partnered with the DragonForce ransomware-as-a-service program. Unit 42 linked this partnership to extortion activity including data theft and encryption.
In 2025, Muddled Libra resumed intrusion operations after 2024 disruption efforts, with Unit 42 assessing the group had become further-reaching, faster, and more impactful. The group targeted organizations in the government, retail, insurance, and aviation sectors.
Federal charges were levied against five suspected Muddled Libra members in November 2024. This was part of broader efforts to disrupt the threat group.
In 2024, Palo Alto Networks Unit 42 reported that Muddled Libra used the Linux userland rootkit bedevil to target VMware vCenter servers. The rootkit used dynamic linker patching to hide LD_PRELOAD persistence more stealthily.
International law enforcement operations disrupted Muddled Libra in mid-to-late 2024, according to Unit 42's assessment of the group's activity. The disruption preceded the group's later return in 2025.
Recent arrests involved four individuals connected to cyberattacks against three UK-based retailers, cited by Unit 42 as related law enforcement action in this threat landscape. The reference does not provide a more specific date for the arrests.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.