Microsoft warns us all to be wary of this devious gift card scam this holiday season

Representational image of a hacker
(Image credit: Shutterstock)

Retail organizations everywhere are being increasingly targeted with phishing attacks as hackers look to commit gift card fraud this holiday season, experts have warned.

A new Microsoft thread posted on X outlines what the company calls a “significant surge” in activity from a threat actor it tracks as Storm-0539. The hackers would first create a malicious landing page and try to get retailers to open them via “highly sophisticated email and SMS phishing”.

These pages allow them to mount adversary-in-the-middle (AiTM) attacks which steal people’s login credentials and session tokens. Those, in turn, allow the threat actors to bypass multi-factor authentication (MFA) and remain in the target environment for longer.

In it for the money

"With each successful compromise, Storm-0539 escalates privileges, moves laterally, and accesses cloud resources to collect specific information," Microsoft says. "Storm-0539 enumerates internal resources and identifies gift card-related services that can be used for gift card fraud."

Furthermore, the hackers use their access to the endpoints to harvest emails, contact lists, and network configurations, which they could use in future attacks against the same organizations, Microsoft added, hinting at the possibility of ransomware infections further down the line. 

To protect against these attacks, the company recommends "building credential hygiene, using security defaults, and securing identities to defend against this threat."

An earlier Microsoft 365 Defender report described Storm-0539 as a financially motivated group active since at least 2021, TheHackerNews reminds. 

"Storm-0539 carries out extensive reconnaissance of targeted organizations in order to craft convincing phishing lures and steal user credentials and tokens for initial access," Microsoft said in its report. "The actor is well-versed in cloud providers and leverages resources from the target organization's cloud services for post-compromise activities."

Stealing gift cards is one of the more popular cybercriminal activities as they’re difficult to trace. Many hackers who steal cryptocurrency decide to spend it on gift cards for the very same reason.

More from TechRadar Pro

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Concept art representing cybersecurity principles
Cybercriminals cashing in on holiday sales rush
Phishing
Russian cyberattackers spotted hitting Microsoft Teams with new phishing campaign
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft authentication system spoofed via phishing attack
Hook on Keyboard
Fake DocuSign and HubSpot phishing emails target 20,000 Microsoft Azure accounts
Hacker Typing
This devious two-step phishing campaign uses Microsoft tools to bypass email security
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Everything you need to know about phishing
Latest in Security
Representational image of a cybercriminal
Criminals are spreading malware disguised as DeepSeek AI
healthcare
Software bug meant NHS information was potentially “vulnerable to hackers”
A hacker wearing a hoodie sitting at a computer, his face hidden.
Experts warn this critical PHP vulnerability could be set to become a global problem
botnet
YouTubers targeted by blackmail campaign to promote malware on their channels
A close-up of a phone screen showing the Telegram, Signal and WhatsApp apps
Agentic AI has “profound” issues with security and privacy, Signal President says
botnet
Another top security camera maker is seeing devices hijacked into botnet
Latest in News
Representational image of a cybercriminal
Criminals are spreading malware disguised as DeepSeek AI
The logo of the social media app Bluesky is seen on the screen of a mobile phone
Bluesky gets a massive video upgrade to tempt X fans who are frustrated by its cyberattack outages
Acer Aspire 14 AI laptop display showing the Windows 11 login screen
Shock, horror – I’m not going to argue with Microsoft’s latest bit of nagging in Windows 11, as this pop-up is justified
Europe
Apple and Meta set to face fines for alleged breaches of EU DMA
Garmin Forerunner 965 on wrist in the dark
New Garmin leak suggests a release is days away, but don't get your hopes up for the Forerunner 975
Xbox Series X
Xbox is reportedly teaming up with a mystery manufacturer to launch a PC gaming handheld this year