Unit 42 has tracked and responded to several waves of intrusion operations conducted by the cybercrime group we track as Muddled Libra (aka Scattered Spider, UNC3944) across different sectors in recent months.
This article contains observations on Muddled Libra thus far in 2025 based on Unit 42 incident response insights. Unit 42 researchers share defensive recommendations that they have seen organizations use successfully against the threat. The researchers also include what’s likely next for this prolific adversary. Muddled Libra’s recent activity follows a series of international law enforcement operations aimed at disrupting the threat group in mid-to-late 2024, including federal charges levied against five suspected members in November 2024. Since that time, Muddled Libra returned with enhanced capabilities, evolving its tradecraft to be further-reaching, faster and more impactful.
Read more…
Source: Palo Alto Unit 42
Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox
Related:
- ShinyHunters hacker in FBI data theft detained in Jordan, cooperating with bureau
October 3, 2026
A suspected member of the ShinyHunters hacking group, which says it stole data on every FBI employee, was detained in Jordan this week and is cooperating with the FBI, three people familiar with the matter told Reuters. Saif al-Din Khader was detained by Jordanian authorities, the three sources said. Two of them said he was brought ...
- Fortinet sounds the alarm over actively exploited FortiMail zero-day
October 2, 2026
Fortinet is warning customers to lock down FortiMail after attackers started exploiting a critical bug that lets them write files to vulnerable systems without logging in. The flaw, tracked as CVE-2026-104286, carries a CVSS score of 9.8 and affects multiple versions of Fortinet’s email security platform. Fortinet describes the vulnerability as a combination of path traversal and ...
- SMTP is the key: BPFDoor and AVERAT hitting the network edge
October 2, 2026
Rapid7 tracked a set of Linux samples that blend into the software and device conventions of the telecom environments they target. The set spans a newly observed BPFDoor variant, a BPF Rekoobe build seen against South Korean targets, a dropper, and six builds of a Linux implant Rapid7 researchers track as AVERAT, deployed against Taiwanese ...
- Operation KillSwitch: Teenager suspected of leading KillSec ransomware group
October 1, 2026
On 30 September 2026, law enforcement took control of KillSec’s leak site, securing at least 110 terabytes of data against further unauthorised access. The cybercrime group used the site to threaten organisations with the publication of stolen files unless they paid a ransom. The action was part of Operation KillSwitch, an international investigation led by German ...
- ShinyHunters hackers are going after Oracle systems once again
September 29, 2026
ShinyHunters have found a way to bypass a mitigation for a zero-day they previously exploited – so now, not only are they back to abusing the same bug, they’ve even expanded their scope to target a much larger pool of organizations. In June 2026, it was reported that ShinyHunters, the infamous data extortionists, found a Java ...
- Dutch police arrest ‘security researcher’ in ShinyHunters probe
September 29, 2026
Dutch police have arrested a 24-year-old man on suspicion of involvement with the prolific ShinyHunters cybercrime group. Cops announced the arrest on Monday night and said the Amsterdam resident would appear before judges at Rotterdam District Court today (Tuesday). Officers have not named the suspect. However, a company has identified a person they believe to be the ...
