Microsoft spots gift card thieves using cyber-espionage tactics
ID: 286d0fd8-2339-5da6-912c-010199b4ffe7
STIX ID: report--286d0fd8-2339-5da6-912c-010199b4ffe7
Feed Name: Bleeping Computer
Microsoft's Cyber Signals report profiles Storm-0539 (aka Ant Lion), a Moroccan financially motivated group that targets organizations issuing gift cards using phishing and account compromise, persists by registering attacker devices with MFA, moves laterally across cloud and enterprise services, abuses pay-as-you-go cloud accounts for infrastructure, and monetizes stolen cards on dark markets; activity spikes around holidays and Microsoft recommends anomaly monitoring, conditional access, token replay protection, least privilege, and FIDO2 for high-risk accounts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
