Muddled Libra: Call Center Exploits as the Gateway to Infiltration

The cybercrime syndicate known as Muddled Libra, also known as Scattered Spider and UNC3944, has recovered in 2025 with more aggressive and damaging activities following worldwide law enforcement actions in 2024, including federal charges against prominent members.

Palo Alto Networks’ Unit 42 incident response teams have witnessed a marked evolution in this adversary’s tactics, techniques, and procedures (TTPs), noting a sharpened focus on leveraging human vulnerabilities via technical social engineering schemes.

Notably, Muddled Libra’s operations have resurged with enhanced capabilities, targeting sectors such as government, retail, insurance, and aviation in rapid succession.

Voice-Based Attacks

While historically favoring technical exploits, Muddled Libra in 2025 has pivoted heavily towards exploiting the human element, particularly through sophisticated “vishing” voice phishing operations.

Attackers impersonate employees, focusing attention on call centers, both internal and outsourced, to reset credentials and circumvent multi-factor authentication (MFA) protections.

Over 70% of observed vishing campaigns involved the use of Google Voice, allowing attackers to mask their identities and further complicate attribution.

Once initial access is obtained, attackers quickly escalate privileges, frequently jumping from first access to domain administrator rights in under an hour.

In some recent incidents, Muddled Libra partnered with the DragonForce ransomware-as-a-service (RaaS) program, exfiltrating vast troves of data, sometimes exceeding 100GB, before executing ransomware payloads to maximize extortion leverage.

Muddled Libra
Speed of Muddled Libra intrusion from initial access to domain admin.

The group demonstrates a preference for “living-off-the-land” tactics minimizing malware use in favor of co-opting legitimate IT management tools, including remote monitoring and management (RMM) platforms, and even exploiting endpoint detection and response (EDR) systems.

Credential harvesting remains a core component of the group’s methodology. Muddled Libra has exhibited the capability to dump enterprise-level password vaults, including Active Directory stores such as NTDS.dit, granting broad access to victim environments.

The group then conducts reconnaissance by accessing Microsoft 365 and SharePoint instances, moving laterally to collect and ultimately exfiltrate sensitive data to external cloud storage, often directly from the compromised environment.

A critical differentiator in the observed impact of Muddled Libra intrusions has been the implementation of robust Conditional Access Policies (CAPs) within Microsoft Entra ID environments.

Organizations with well-configured CAPs including blocking unmanaged device access, enforcing location-based authentication, and requiring on-premises setup for MFA were able to materially slow attacker progress, buying valuable time for containment and response.

Muddled Libra
Muddled Libra tradecraft evolution.

Proactive organizations have also adopted layered defenses: intelligence-driven training for IT support staff to spot social engineering, strict procedures for credential resets, enforcing least privilege principles, and closely monitoring identity and access management changes, particularly in cloud environments.

Building robust incident response plans and out-of-band communications capabilities should traditional channels be compromised further contributes to containment.

RaaS Partnerships

According to the report, As Muddled Libra continues to ally with RaaS operators such as Akira, ALPHV, DragonForce, and others, the operational model of streamlined data exfiltration and extortion is set to persist.

The group’s demonstrated cloud-first mindset, combined with sophisticated manipulation of user trust mechanisms, underscores the need for heightened vigilance and rapid information sharing between private organizations and law enforcement.

Recent arrests tied to Muddled Libra-affiliated attacks in the UK highlight the potential deterrent effect of coordinated international response, though the group is expected to adapt and continue targeting poorly secured environments.

At its core, defending against Muddled Libra requires an integrated approach balancing technical controls and human awareness to counteract a threat actor that leverages both advanced technology and the inevitabilities of human error as key gateways for organizational infiltration.

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates

Mandvi
Mandvi
Mandvi is a Security Reporter covering data breaches, malware, cyberattacks, data leaks, and more at Cyber Press.

Trending News

Related Stories