A threat actor tracked as “Muddled Libra” is using the 0ktapus phishing kit to gain initial access to organizations in the software automation, business process outsourcing, telecommunications, and technology industries, according to researchers at Palo Alto Networks’ Unit 42.
“Muddled Libra investigations demonstrate the use of an unusually large attack toolkit,” the researchers write. “Their arsenal ranges from hands-on social engineering and smishing attacks to proficiency with niche penetration testing and forensics tools, giving this threat group an edge over even a robust and modern cyber defense plan. In the incidents the Unit 42 team has investigated, Muddled Libra has been methodical in pursuing their goals and highly flexible with their attack strategies. When an attack path is blocked, they have either rapidly pivoted to another vector or modified the environment to allow their favored path.”
After gaining access to an organization’s network, the group is extremely persistent.
“The Muddled Libra threat group has also repeatedly demonstrated a strong understanding of the modern incident response (IR) framework,” the researchers write. “This knowledge allows them to continue progressing toward their goals even as incident responders attempt to expel them from an environment. Once established, this threat group is difficult to eradicate. Muddled Libra has shown a penchant for targeting a victim’s downstream customers using stolen data and, if allowed, they will return repeatedly to the well to refresh their stolen dataset. Using this stolen data, the threat actor has the ability to return to prior victims even after initial incident response. This demonstrates the attacker’s tenacity even after initially being discovered.”
The threat actor is also able to use their access to launch supply-chain attacks against their victims’ clients.
“Furthermore, Muddled Libra has appeared to have clear goals for their breaches versus just capitalizing on opportunistic access,” Unit 42 says. “They’ve rapidly sought and stolen information on downstream client environments and then used it to pivot into those environments. They have demonstrated a strong understanding of their victims’ high-value clients and what information would be most useful for follow-on attacks.”
New-school security awareness training can enable your employees to thwart phishing attacks so they can prevent threat actors from gaining access to your environment.