Observing Atlas Lion (part one): Why take control when you can enroll?
ID: 276f4527-7c80-5d3b-8849-f71d1f47d488
STIX ID: report--276f4527-7c80-5d3b-8849-f71d1f47d488
Feed Name: Expel Blog
Threat Score
Atlas Lion, a Morocco-based cybercrime group targeting gift-card issuers, used SMS phishing to capture credentials and session cookies, registered their own MFA device, and enrolled attacker-controlled Azure VMs into a victim's Entra ID so the VMs appeared as legitimate corporate devices; the attack was detected when Defender flagged a known-malicious IP during automated endpoint onboarding and was remediated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
