logo

Moroccan cybercrime group Atlas Lion hiding in plain sight during attacks on retailers

ID: 1d9e21c1-6ae1-5ad6-bc89-ad0f4b4746dc

STIX ID: report--1d9e21c1-6ae1-5ad6-bc89-ad0f4b4746dc

Feed Name: The Record from Recorded Future News

Threat Score
75/100

Date Published: 2025-04-10

Date Updated: 2026-05-01

...
...

Researchers observed Atlas Lion using phishing to harvest credentials and MFA codes, enrolling attacker-controlled Azure VMs into corporate domains to appear as legitimate devices, and then abusing access to obtain internal documentation and issue fraudulent gift cards; the technique leverages cloud infrastructure and MFA enrollment flows to bypass device protections, though defenders detected the activity due to compliance software and a flagged malicious IP.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.