logo

Microsoft spots gift card thieves using cyber-espionage tactics

ID: 286d0fd8-2339-5da6-912c-010199b4ffe7

STIX ID: report--286d0fd8-2339-5da6-912c-010199b4ffe7

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2024-05-23

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Microsoft's Cyber Signals report profiles Storm-0539 (aka Ant Lion), a Moroccan financially motivated group that targets organizations issuing gift cards using phishing and account compromise, persists by registering attacker devices with MFA, moves laterally across cloud and enterprise services, abuses pay-as-you-go cloud accounts for infrastructure, and monetizes stolen cards on dark markets; activity spikes around holidays and Microsoft recommends anomaly monitoring, conditional access, token replay protection, least privilege, and FIDO2 for high-risk accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.