{"id":3724,"date":"2024-05-23T13:41:33","date_gmt":"2024-05-23T18:41:33","guid":{"rendered":"https:\/\/www.darkreading.com\/threat-intelligence\/new-gift-card-scam-targets-retailers-not-buyers-to-print-endless-money"},"modified":"2024-05-23T13:41:33","modified_gmt":"2024-05-23T18:41:33","slug":"new-gift-card-scam-targets-retailers-not-buyers-to-print-endless","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/23\/new-gift-card-scam-targets-retailers-not-buyers-to-print-endless\/","title":{"rendered":"New Gift Card Scam Targets Retailers, Not Buyers, to Print Endless $$$"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt7058bf650a93b3b6\/664f8422a2f90661e5f3da74\/Gift_cards-Zoonar_GmbH-Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/new-gift-card-scam-targets-retailers-not-buyers-to-print-endless.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/new-gift-card-scam-targets-retailers-not-buyers-to-print-endless.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A Moroccan threat group has upgraded the classic gift card scam by targeting not retail customers but the systems that register the cards, allowing them to &#8220;print&#8221; money at will.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Scammers have been using social engineering tactics to convince regular people to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/gift-cards-convenient-and-easy-to-hack\" rel=\"noopener\">buy them gift cards for years<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. The playbook hasn&#8217;t changed much over time, because it hasn&#8217;t had to; it&#8217;s as <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/apple-gift-card-scammers-sentenced-for-role-in-1-5m-fraud\" rel=\"noopener\">effective and profitable today<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> as ever.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Perhaps that&#8217;s why the so-called Storm-0539 cybercrime group&#8217;s latest campaign stands out: it took something that wasn&#8217;t broken and made it better. Instead of having to work individual victims \u2014 always labor-intensive, with a potentially low rate of return \u2014 the attackers compromise the retailers themselves, specifically the portals they use to issue gift cards.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Here&#8217;s how it works, according to a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2024\/05\/23\/cyber-signals-inside-the-growing-risk-of-gift-card-fraud\/\" rel=\"noopener\">new report from Microsoft<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Nouveau Gift Card Racket\">Nouveau Gift Card Racket<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Instead of retail customers, Storm-0539 targets retail employees with phishing texts. The aim of its social engineering is to compromise their employer accounts.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Using an employee&#8217;s account, the cybercriminals can begin to see into and move laterally within a retailer&#8217;s network. Sometimes they&#8217;ll use the first employee to compromise others, with phishing attempts sent through internal mailing lists that mimic the company&#8217;s usual norms of business. Otherwise, with access to accounts of sufficient privilege, they steal information about various services and accounts they can then use to ultimately reach the part of the system that handles gift cards.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Storm-0539 gathers information on a wide variety of resources in targeted environments to advance toward its objective to steal gift cards,&#8221; notes Emiel Haeghebaert, senior hunt analyst at the Microsoft Threat Intelligence Center. This might include resources relating to OneDrive, Salesforce, Citrix, and more, he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Case in point: &#8220;When the group targets resources such as SharePoint or VPN appliances, this is typically because those resources contain additional information or enable access that is required to ultimately access gift card infrastructure,&#8221; he says. &#8220;For example, many organizations require an active VPN connection before users can access sensitive files and resources. Therefore, Storm-0539 may have to first obtain access to VPN resources and documentation before being able to continue with the intrusion.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As Microsoft tells it, Storm-0539&#8217;s reconnaissance and cloud skills are at the level of what it observes from nation-state-level actors.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Through whatever means necessary to get there, Storm-0539 wades through retailers&#8217; environments until it obtains access to their gift card portal. Using a compromised employee account, it creates as many new gift cards as possible, worth just shy of whatever arbitrary dollar amount limit the retailer has set, and as quickly as possible. It then cashes them out, or uses money mules to cash them out, or sells them to other malicious actors on the Dark Web.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Combatting Storm-0593\">Combatting Storm-0593<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The timing of Microsoft&#8217;s reporting is deliberate. Predictably, Storm-0593 always ramps up in anticipation of <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/holiday-spam-phishing-campaigns-challenge-retailers\" rel=\"noopener\">holiday seasons<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">: summer, Labor Day, Thanksgiving, Black Friday, winter holidays, and, this weekend, Memorial Day. The group&#8217;s malicious activity from September to December 2023, for example, was 60% higher than usual, and it&#8217;s been up 30% in the past few months.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">To prepare for this threat actor, and the others that inevitably will follow it, Microsoft recommends that organizations adopt phishing-resistant multifactor authentication (MFA), strict password reset measures, token replay and other fraud protections, and principles of least privilege, as well as educate employees on the risks of this scam.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The difference good security makes here has already been proven. Thanks to increased collaboration and information-sharing, Microsoft reports, &#8220;We have observed an increase in major retailers\u2019 ability to effectively ward off Storm-0539 activity in recent months.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/new-gift-card-scam-targets-retailers-not-buyers-to-print-endless-money\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A Moroccan threat group has upgraded the classic gift card<\/p>\n","protected":false},"author":12,"featured_media":3725,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3724","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/new-gift-card-scam-targets-retailers-not-buyers-to-print-endless-scaled.jpg?fit=2560%2C1700&ssl=1",2560,1700,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/new-gift-card-scam-targets-retailers-not-buyers-to-print-endless-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/new-gift-card-scam-targets-retailers-not-buyers-to-print-endless-scaled.jpg?fit=300%2C199&ssl=1",300,199,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/new-gift-card-scam-targets-retailers-not-buyers-to-print-endless-scaled.jpg?fit=640%2C425&ssl=1",640,425,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/new-gift-card-scam-targets-retailers-not-buyers-to-print-endless-scaled.jpg?fit=640%2C425&ssl=1",640,425,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/new-gift-card-scam-targets-retailers-not-buyers-to-print-endless-scaled.jpg?fit=1536%2C1020&ssl=1",1536,1020,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/new-gift-card-scam-targets-retailers-not-buyers-to-print-endless-scaled.jpg?fit=2048%2C1360&ssl=1",2048,1360,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/new-gift-card-scam-targets-retailers-not-buyers-to-print-endless-scaled.jpg?fit=1024%2C680&ssl=1",1024,680,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/new-gift-card-scam-targets-retailers-not-buyers-to-print-endless-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/new-gift-card-scam-targets-retailers-not-buyers-to-print-endless-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/new-gift-card-scam-targets-retailers-not-buyers-to-print-endless-scaled.jpg?fit=2560%2C1700&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3724","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3724"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3724\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3725"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3724"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3724"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3724"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}