Atlas Lion Campaign Exploits Device Enrollment and MFA for Persistence (Campaign)
ID: 2df2476c-b1fd-51c9-8498-e8c8b332f8e6
STIX ID: report--2df2476c-b1fd-51c9-8498-e8c8b332f8e6
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-04-10
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Atlas Lion executed an SMS phishing campaign to harvest user credentials and MFA codes, registered an attacker-controlled Azure VM into the target environment to onboard a malicious MFA device, and leveraged validated credentials for rapid reconnaissance of internal services (SharePoint, Confluence) and privilege-escalation attempts; endpoint detections based on a known malicious IP triggered SOC response and removal of the attacker VM.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
