STORM-0539, also known as Atlas Lion, is a financially motivated cybercriminal threat actor focused on gift card fraud against large retail and consumer-facing enterprises. The actor has been publicly linked to campaigns targeting gift card operations within corporate environments, especially employees associated with gift card departments and related approval or support workflows. Reporting also associates overlapping activity with the campaign cluster CL-CRI-1032 and the intrusion set referred to as Jingle Thief. The group commonly uses phishing and SMS phishing to obtain employee credentials and initial access, including targeting both personal and work mobile devices. It has used phishing infrastructure and kits capable of bypassing multi-factor authentication, then expanded access through follow-on phishing against additional internal users. Once inside a victim environment, STORM-0539 conducts reconnaissance to identify gift card issuance processes, related documentation, approval chains, remote access procedures, and personnel with access to relevant systems. The actor has also sought SSH credentials and keys where available. A notable characteristic of this activity is heavy abuse of cloud identity and collaboration platforms, particularly Microsoft 365 services such as Exchange, SharePoint, OneDrive, and Entra ID. The actor has used compromised cloud accounts for internal phishing, mailbox monitoring, inbox forwarding rules, and message manipulation to conceal malicious activity and observe financial and IT workflows. For persistence, the group has abused legitimate identity features including self-service password reset, rogue authenticator registration, and attacker-controlled device enrollment, enabling continued access even after defensive remediation steps such as password resets. STORM-0539’s end goal is unauthorized acquisition of gift card value for resale and financial gain. Observed fraud methods include creating fraudulent gift cards through compromised employee accounts and, when controls blocked direct issuance, pivoting to takeover of unredeemed gift cards by altering associated account details to enable redemption. The actor has also exfiltrated employee data, including contact and account information, which can support additional attacks or monetization. Activity has been observed over extended dwell times and broad internal compromise, indicating a disciplined post-compromise workflow centered on stealth, persistence, and monetization rather than disruptive effects.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Microsoft-tracked activity name assessed in the content to overlap with Unit 42’s CL-CRI-1032/Jingle Thief gift-card-fraud-focused, cloud identity abuse operations.
Financially motivated cybercriminal activity targeting US retail corporate employees via smishing and phishing to compromise accounts, move laterally, access gift card department systems, and create or hijack gift cards for fraud; also exfiltrates employee data for follow-on abuse or sale.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.