A financially motivated threat group operating out of Morocco has orchestrated a sophisticated campaign, dubbed Jingle Thief, targeting global retailers and businesses that issue gift cards. The attackers focus on exploiting cloud-based infrastructure, particularly Microsoft 365 environments, to conduct large-scale gift card fraud, especially during festive seasons when such fraud is more lucrative. The campaign begins with spear-phishing and smishing attacks aimed at harvesting employee credentials through convincing fake login portals that mimic legitimate services. Once initial access is gained, the attackers authenticate directly to Microsoft 365, bypassing traditional malware and endpoint-based techniques. They conduct extensive reconnaissance within the compromised environment, searching file shares, OneDrive, and SharePoint for documents related to gift card issuance workflows, ticketing systems, and internal processes. The attackers also seek out VPN configuration files and virtual machine access guides to deepen their foothold. Persistence is maintained by compromising additional accounts through internal phishing, leveraging the trust inherent in internal communications. The attackers use stealthy tactics, such as moving sent phishing emails and user replies to Deleted Items, to evade detection by both users and security teams. Their operations are notable for the ability to remain undetected within organizations for extended periods, sometimes exceeding a year, allowing them to gain deep familiarity with internal systems and processes. The campaign has been observed to launch coordinated attacks across multiple enterprises, with a particular focus on those heavily reliant on cloud services. The threat actors behind Jingle Thief are tracked as cluster CL-CRI-1032 by Unit 42 and are believed to overlap with groups known as Atlas Lion and STORM-0539. The attackers' cloud-only approach, avoiding malware and endpoint compromise, makes detection and remediation particularly challenging for targeted organizations. The campaign highlights the growing risk of identity-based attacks in cloud environments, where user credentials are the primary target. Security researchers emphasize the need for robust identity and access management, vigilant monitoring of cloud activity, and user education to mitigate such threats. The incident underscores the evolving tactics of financially motivated threat actors and the importance of adapting security strategies to address cloud-native attack vectors. Organizations are advised to review their gift card issuance processes, strengthen multi-factor authentication, and monitor for unusual access patterns in cloud services. The Jingle Thief campaign serves as a warning of the increasing sophistication and persistence of cloud-focused cybercriminals targeting the retail sector.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Unit 42 published research on the cloud-based gift card fraud campaign, tracking it as CL-CRI-1032 and noting overlap with publicly reported Atlas Lion and STORM-0539 activity. The report detailed the actors' use of phishing, internal cloud abuse, mailbox manipulation, and Entra ID self-service/device enrollment features for persistence.
During April and May 2025, Unit 42 observed a coordinated wave of attacks affecting multiple global enterprises. In one case, the activity involved more than 60 compromised user accounts and was aimed at enabling unauthorized issuance of high-value gift cards.
In at least one observed intrusion, the attackers retained access to a victim environment for roughly 10 months while abusing Microsoft 365 and Entra ID features for persistence and stealth. This indicates the campaign was capable of sustained, low-noise cloud-based compromise.
Unit 42 assessed with moderate confidence that the actors behind the "Jingle Thief" campaign have been active since 2021. The group focused on financially motivated gift card fraud, particularly targeting retailers around holiday periods.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 27 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
6 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcescworld.com
Open sourcethehackernews.com
Open sourceforesiet.com
Open sourceunit42.paloaltonetworks.com
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.