Muddled Libra — Ransomware Profile

Muddled Libra is Palo Alto Networks Unit 42's designation for a financially motivated, English-speaking cybercrime cluster that breaks into enterprises through help-desk and call-centre social engineering rather than novel malware. Unit 42's 2023 debut presented it as distinct from the 0ktapus, Scattered Spider and Scatter Swine clusters that share the same phishing toolkit; its current assessment instead calls Muddled Libra "a subset of a loosely affiliated threat collective known as Scattered Spider, Octo Tempest, Oktapus and other names", and Unit 42's own tracked-groups index maps the name onto MITRE ATT&CK G1015 (Scattered Spider), UNC3944 and Octo Tempest. The group monetises intrusions as a ransomware affiliate, joining the ALPHV/BlackCat programme in 2023 and partnering with DragonForce from April 2025. No vendor attributes it to a nation-state or to a single country of origin: charged and convicted members have been US, UK and dual nationals drawn from the transnational "The Com" community, and Unit 42's observation that targets are "primarily in the U.S." describes victims, not operators.

IntelFusions coverage (2)

Vendor research

Read the full analysis on IntelFusions