Jingle Thief: Inside a Cloud-Based Gift Card Fraud Campaign
ID: 21f0b1ab-2b13-57c2-a27d-212bed36244f
STIX ID: report--21f0b1ab-2b13-57c2-a27d-212bed36244f
Feed Name: Palo Alto Networks Unit 42
Jingle Thief is a Unit 42 investigation into a financially motivated Morocco-based campaign that uses targeted phishing and smishing to harvest Microsoft 365 credentials, perform extensive cloud reconnaissance of SharePoint/OneDrive, and maintain long-term persistence (including rogue device/enrolment and mailbox rules) to issue and monetise high-value gift cards; the report includes IoCs (multiple Moroccan IPs, ASNs, phishing URL patterns), MITRE mappings, and recommended detections and mitigations using Cortex XDR/UEBA/ITDR.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
