• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
moroccan cybercrime group steals up to $100k daily through gift

Moroccan Cybercrime Group Steals Up to $100K Daily Through Gift Card Fraud

You are here: Home / General Cyber Security News / Moroccan Cybercrime Group Steals Up to $100K Daily Through Gift Card Fraud
May 27, 2024

Microsoft is calling attention to a Morocco-based cybercrime group dubbed Storm-0539 that’s behind gift card fraud and theft through highly sophisticated email and SMS phishing attacks.

“Their primary motivation is to steal gift cards and profit by selling them online at a discounted rate,” the company said in its latest Cyber Signals report. “We’ve seen some examples where the threat actor has stolen up to $100,000 a day at certain companies.”

Storm-0539 was first spotlighted by Microsoft in mid-December 2023, linking it to social engineering campaigns ahead of the year-end holiday season to steal victims’ credentials and session tokens via adversary-in-the-middle (AitM) phishing pages.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


The gang, also called Atlas Lion and active since at least late 2021, is known to then abuse the initial access to register their own devices to bypass authentication and obtain persistent access, gain elevated privileges, and compromise gift card-related services by creating bogus gift cards to facilitate fraud.

Cybersecurity

The attack chains are further designed to gain covert access to a victim’s cloud environment, allowing the threat actor to carry out extensive reconnaissance and weaponize the infrastructure to achieve their end goals. Targets of the campaign include large retailers, luxury brands, and well-known fast-food restaurants.

The end goal of the operation is to redeem the value associated with those cards, sell the gift cards to other threat actors on black markets, or use money mules to cash out the gift cards.

The criminal targeting of gift card portals marks a tactical evolution of the threat actor, which has previously engaged in stealing payment card data by using malware on point-of-sale (PoS) devices.

The Windows maker said it observed a 30% increase in Storm-0539 intrusion activity between March and May 2024, describing the attackers as leveraging their deep knowledge of the cloud to “conduct reconnaissance on an organization’s gift card issuance processes.”

Earlier this month, the U.S. Federal Bureau of Investigation (FBI) released an advisory [PDF] warning of smishing attacks perpetrated by the group targeting the gift card departments of retail corporations using a sophisticated phishing kit to bypass multi-factor authentication (MFA).

“In one instance, a corporation detected Storm-0539’s fraudulent gift card activity in their system, and instituted changes to prevent the creation of fraudulent gift cards,” the FBI said.

“Storm-0539 actors continued their smishing attacks and regained access to corporate systems. Then, the actors pivoted tactics to locating unredeemed gift cards, and changed the associated email addresses to ones controlled by Storm-0539 actors in order to redeem the gift cards.”

It’s worth noting that the threat actor’s activities go beyond stealing the login credentials of gift card department personnel, their efforts also extend to acquiring secure shell (SSH) passwords and keys, which could then be sold for financial gain or used for follow-on attacks.

Another tactic adopted by Storm-0539 entails the use of legitimate internal company mailing lists to disseminate phishing messages upon gaining initial access, adding a veneer of authenticity to the attacks. It has also been found creating free trials or student accounts on cloud service platforms to set up new websites.

The abuse of cloud infrastructure, including by impersonating legitimate non-profits to cloud service providers, is a sign that financially motivated groups are borrowing a page out of advanced state-sponsored actors’ playbooks to camouflage their operations and remain undetected.

Microsoft is urging companies that issue gift cards to treat their gift card portals as high-value targets by monitoring for suspicious logins.

“Organizations should also consider complementing MFA with conditional access policies where authentication requests are evaluated using additional identity-driven signals like IP address location information or device status, among others,” the company noted.

“Storm-0539 operations are persuasive due to the actor’s use of legitimate compromised emails and the mimicking of legitimate platforms used by the targeted company.”

Cybersecurity

The development comes as Enea revealed details of criminal campaigns that exploit cloud storage services like Amazon S3, Google Cloud Storage, Backblaze B2, and IBM Cloud Object Storage for SMS-based gift card scams that redirect users to malicious websites with an aim to plunder sensitive information.

“The URL linking to the cloud storage is distributed via text messages, which appear to be authentic and can therefore bypass firewall restrictions,” Enea researcher Manoj Kumar said.

“When mobile users click on these links, which contain well-known cloud platform domains, they are directed to the static website stored in the storage bucket. This website then automatically forwards or redirects users to the embedded spam URLs or dynamically generated URLs using JavaScript, all without the user’s awareness.”

In early April 2023, Enea also uncovered campaigns that involve URLs constructed using the legitimate Google address, “google.com/amp,” which is then combined with encoded characters to conceal the scam URL.

“This kind of trust is being exploited by malicious actors trying to trick mobile subscribers by hiding behind seemingly legitimate URLs,” Kumar pointed out. “Attacker techniques can include luring subscribers to their websites under false pretenses, and stealing sensitive information such as credit card details, email or social media credentials, and other personal data.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «report: the dark side of phishing protection Report: The Dark Side of Phishing Protection
Next Post: TP-Link Gaming Router Vulnerability Exposes Users to Remote Code Attacks tp link gaming router vulnerability exposes users to remote code attacks»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • New HTTPBot Botnet Launches 200+ Precision DDoS Attacks on Gaming and Tech Sectors
  • Top 10 Best Practices for Effective Data Protection
  • Researchers Expose New Intel CPU Flaws Enabling Memory Leaks and Spectre v2 Attacks
  • Fileless Remcos RAT Delivered via LNK Files and MSHTA in PowerShell-Based Attacks
  • [Webinar] From Code to Cloud to SOC: Learn a Smarter Way to Defend Modern Applications
  • Meta to Train AI on E.U. User Data From May 27 Without Consent; Noyb Threatens Lawsuit
  • Coinbase Agents Bribed, Data of ~1% Users Leaked; $20M Extortion Attempt Fails
  • Pen Testing for Compliance Only? It’s Time to Change Your Approach
  • 5 BCDR Essentials for Effective Ransomware Defense
  • Russia-Linked APT28 Exploited MDaemon Zero-Day to Hack Government Webmail Servers

Copyright © TheCyberSecurity.News, All Rights Reserved.