Atlas Lion is a financially motivated threat actor associated with cloud-centric fraud operations against enterprises that issue gift cards. Reporting overlaps Atlas Lion with STORM-0539 and Unit 42 cluster CL-CRI-1032, and assesses the activity to be operated by Morocco-based attackers active since at least 2021. The actor’s campaigns are characterized by credential theft through phishing and smishing, followed by extensive abuse of Microsoft 365 cloud services to conduct reconnaissance, persistence, internal phishing, and fraud execution. Atlas Lion primarily targets retail and consumer services organizations, especially enterprises with gift card issuance workflows and cloud-based identity and collaboration environments. The actor mines SharePoint, OneDrive, Exchange, and Entra ID for internal documentation, approval processes, remote-access guidance, and operational procedures related to gift card issuance. After initial compromise, Atlas Lion expands access by sending phishing messages from compromised internal accounts, enabling lateral movement and broader account compromise inside victim tenants. A defining feature of Atlas Lion activity is persistence through legitimate identity-platform features rather than malware-heavy tradecraft. The actor has been observed registering rogue authenticator applications, abusing self-service password reset mechanisms, and enrolling attacker-controlled devices in Entra ID to preserve access even after remediation steps such as password changes. Atlas Lion also uses mailbox forwarding rules and message manipulation to passively monitor victim communications, particularly around approvals, financial workflows, and IT account changes, while reducing the chance of detection. The actor’s operations are geared toward unauthorized issuance and monetization of high-value gift cards, with activity often intensifying during holiday periods when staffing is reduced and gift card demand is elevated. Tradecraft emphasizes stealth within SaaS environments, low forensic visibility, and prolonged access. In observed intrusions, Atlas Lion maintained access for extended periods and compromised large numbers of user accounts within a single enterprise. The group is best understood as a financially motivated cloud-focused fraud actor rather than a ransomware or destructive operator.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Publicly tracked threat actor assessed to overlap with Unit 42’s CL-CRI-1032/Jingle Thief activity, associated here with Morocco-based, financially motivated cloud identity abuse leading to gift card fraud.
Financially motivated threat actor tracked by Microsoft as a Storm cluster.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.