logo

Atlas Lion Campaign Exploits Device Enrollment and MFA for Persistence (Campaign)

ID: 2df2476c-b1fd-51c9-8498-e8c8b332f8e6

STIX ID: report--2df2476c-b1fd-51c9-8498-e8c8b332f8e6

Feed Name: Wiz Cloud Threat Landscape

Threat Score
72/100

Date Published: 2025-04-10

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Atlas Lion executed an SMS phishing campaign to harvest user credentials and MFA codes, registered an attacker-controlled Azure VM into the target environment to onboard a malicious MFA device, and leveraged validated credentials for rapid reconnaissance of internal services (SharePoint, Confluence) and privilege-escalation attempts; endpoint detections based on a known malicious IP triggered SOC response and removal of the attacker VM.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.