Cyber Threat Report: 'Muddled Libra’s Evolution to the Cloud'
Report Author | Palo Alto Unit 42 |
---|---|
Publication Date | 2024-04-10 |
Original Reporting | Source |
Related Intrusion Sets | Muddled Libra |
Researchers at Unit 42 report on evolution of the Muddled Libra group as the target SaaS (software-as-a-service) applications and CSP (cloud service provider) environments, leveraging data acquired for attack progression and extortion. The group uses social engineering to target administrative users, exploits identity providers for privilege escalation, and utilizes CSP services for data exfiltration. As well as outlining TTPs used by the group, the article suggests mitigations to defend against Muddled Libra, including implementing robust protections for Identity Portals and CSP identities.
Cyber Threat Graph Context
Explore how this report relates to the wider threat graph