Moroccan cybercrime group impersonates nonprofits and abuses cloud services to rake in gift card cash
ID: 38195320-7284-5312-9dc6-e0d1d408c848
STIX ID: report--38195320-7284-5312-9dc6-e0d1d408c848
Feed Name: CyberScoop
Microsoft researchers and the FBI describe Storm-0539 (Atlas Lion), a Morocco-based, financially motivated cybercrime group that impersonates legitimate nonprofits to obtain free or reduced cloud resources which they use to host infrastructure for large-scale gift card theft campaigns targeting major U.S. retailers. The group performs targeted phishing of employees involved in payment and gift card operations, bypasses multi-factor authentication by adding attacker-controlled phones to accounts, and leverages deep knowledge of cloud environments and company gift-card policies to stay below detection thresholds; activity has increased since late 2021.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
