logo

Observing Atlas Lion (part one): Why take control when you can enroll?

ID: 276f4527-7c80-5d3b-8849-f71d1f47d488

STIX ID: report--276f4527-7c80-5d3b-8849-f71d1f47d488

Feed Name: Expel Blog

Threat Score
70/100

Date Published: 2025-04-10

Date Updated: 2026-04-27

Author: Ben Nahorney; Jenni Maynard

...
...

Atlas Lion, a Morocco-based cybercrime group targeting gift-card issuers, used SMS phishing to capture credentials and session cookies, registered their own MFA device, and enrolled attacker-controlled Azure VMs into a victim's Entra ID so the VMs appeared as legitimate corporate devices; the attack was detected when Defender flagged a known-malicious IP during automated endpoint onboarding and was remediated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.