216.73.216.226

Jingle Thief: Inside a Cloud-Based Gift Card Fraud Campaign

· Published 22/10/2025 11:21 · Modified 22/10/2025 15:05

Export JSON

Essential information

Published
22/10/2025 11:21
Modified
22/10/2025 15:05
Tags
2025-10-22 cloud-based attacks gift card fraud identity-based threats microsoft 365 phishing smishing
Related entities
1 intrusion sets (apt), 4 techniques (mitre), 3 others

Description

The Jingle Thief campaign, conducted by financially motivated threat actors from Morocco, targets global enterprises in retail and consumer services sectors to execute . Using and tactics, the attackers gain access to environments, exploiting cloud services for reconnaissance, lateral movement, and persistence. They focus on compromising gift card issuance systems, leveraging internal documentation and communication channels. The campaign demonstrates sophisticated techniques, including tailored , internal email manipulation, and device registration abuse. The attackers maintain long-term access, sometimes over a year, making detection challenging. Their activities often align with holiday periods to maximize impact.

External references