Malware News Ever seen an attacker perform an internet speed test? Muddled Libra did just that while trying to steal email files.

Khushal

Level 13
Thread author
Verified
Top Poster
Well-known
Apr 4, 2024
601
3,614
1,169

During a September 2025 incident response investigation, Unit 42 discovered a rogue virtual machine (VM) which we believe with high confidence to be used by the cybercrime group Muddled Libra (aka Scattered Spider, UNC3944). The contents of this rogue VM and activity from the attack provide valuable insight into the operational playbook of this threat actor.
 
Muddled Libra is already bordering on the surreal and straight out of a manual… but a home user’s manual: before stealing emails, they stop to check the internet speed. I can already picture them complaining to the ISP because the loot won’t download in 4K. 📡📉🤣