Read on app Read on app
✕
Prayer Times
  • Morocco
  • Lifestyle
  • Western Sahara
  • Login
Morocco World News
  • Home
  • Culture
  • Politics
  • Society
  • Economy
  • Opinion
  • Education
  • Sustainability
  • Tech
  • Sport
  • World Cup 2026
No Result
View All Result
Morocco World News
  • Home
  • Culture
  • Politics
  • Society
  • Economy
  • Opinion
  • Education
  • Sustainability
  • Tech
  • Sport
  • World Cup 2026
No Result
View All Result
Morocco World News

Home » News » Moroccan Cybercriminals Steal Millions Through Sophisticated Gift Card Scheme

Moroccan Cybercriminals Steal Millions Through Sophisticated Gift Card Scheme

The cybersecurity specialist group Unit 42 presented an end-to-end analysis of the Moroccan-based “Jingle Thief” campaign, detailing its full lifecycle through real-world incident telemetry and detection data.

Adil FaouzibyAdil Faouzi
Oct, 27, 2025
0 0
A A
A sophisticated cybercrime campaign orchestrated by Morocco-based threat actors has been targeting global retail and consumer services companies to steal and monetize gift cards.

A sophisticated cybercrime campaign orchestrated by Morocco-based threat actors has been targeting global retail and consumer services companies to steal and monetize gift cards.

Marrakech – A sophisticated cybercrime campaign orchestrated by Morocco-based threat actors has been targeting global retail and consumer services companies to steal and monetize gift cards. The operation, dubbed “Jingle Thief,” exploits cloud-based infrastructure to conduct large-scale gift card fraud, particularly during holiday seasons.

According to Unit 42, which is part of Palo Alto Networks, the financially motivated attackers have been active since 2021.

“What makes the threat actor behind this activity particularly dangerous is the ability to maintain a foothold inside organizations for extended periods – sometimes over a year,” the cybersecurity research team reported. During April and May 2025, the group launched coordinated attacks against multiple global enterprises.

The investigation revealed that in one case, the attackers maintained access for approximately 10 months and compromised over 60 user accounts within a single global enterprise.

The threat actors use phishing and SMS-based “smishing” to steal credentials from organizations that issue gift cards. Once inside, they exploit Microsoft 365 services, including SharePoint, OneDrive, Exchange, and Entra ID.

The threat actors often align their activity with holiday periods, increasing operations during times of reduced staffing and heightened gift card spending.

“Unlike threat actors who rely on commodity malware or endpoint exploitation, the attackers behind CL‑CRI‑1032 operate almost exclusively in cloud environments once they obtain credentials through phishing,” Unit 42 researchers noted.

The activity cluster is tracked as CL-CRI-1032, with researchers assessing “with moderate confidence” that it overlaps with threat actors publicly known as Atlas Lion and STORM-0539.

Having gained initial access, the threat actors conducted reconnaissance to map the environment, moved laterally to access more sensitive areas, and identified opportunities to execute large-scale financial fraud.

The final attack step of device registration creates a foothold that the threat actors exploit to issue gift cards, which they then leverage for monetary gain.

Why do attackers target gift cards specifically?

The cybercriminals craft highly convincing phishing content tailored to each target organization. They gather intelligence on branding, login portals, and email templates to create authentic-looking phishing pages.

Some lures impersonate nonprofits or non-governmental organizations (NGOs), likely to give the appearance of credibility and increase victim engagement.

Many of their messages are delivered using self-hosted PHP mailer scripts from compromised WordPress servers to obscure their origin.

Phishing URLs often include the organization’s name, a trusted third-party tool or software, and landing pages that closely mimic legitimate login screens.

The attackers employ deceptive URL formatting tactics. For example, a URL might appear to point to a legitimate domain but actually navigates to a malicious site.

One technique involves using the format: https://organization[.][email protected][/]workspace, where browsers interpret everything before the @ as user credentials.

Gift cards are the primary target because of their ease of redemption and rapid monetization. “Threat actors resell gift cards on gray-market forums at discounted rates, enabling near-instant cash flow,” Unit 42 explained.

Additional factors making gift cards attractive include minimal personal information required for redemption, difficulty in tracing fraud, and wide acceptance.

Retail environments are particularly vulnerable to this type of attack, as gift card systems are often accessible to a wide range of internal users, such as store employees. These systems may support multiple vendors or programs, making access pathways broader and more difficult to control.

IP addresses and ASNs trace back to Morocco

The investigation uncovered repeated access attempts against multiple gift card issuance applications. The attackers tried to issue high-value cards across different programs to monetize them, possibly using the cards as collateral in money-laundering schemes.

These operations were staged in a way that minimizes logging and forensic traces, reducing the chance of rapid detection.

Unit 42 detected numerous suspicious activities related to the campaign, including VPN access with abnormal operating systems, first connections from new countries, and suspicious SSO (Single Sign-On) access. Alerts included “impossible traveler” scenarios where login attempts occurred from geographically distant locations in implausibly short timeframes.

Unit 42 identified multiple IP addresses linked to the operation, all geolocated to Morocco. The infrastructure includes addresses such as 105.156.109[.]227, 160.176.128[.]242, and 196.89.141[.]80, among others. The associated ASN organizations also geolocated to Morocco are MT-MPLS, ASMedi, and MAROCCONNECT.

Additionally, the attackers used US infrastructure, potentially as proxies or compromised hosts, including IP addresses 70.187.192[.]236 and 72.49.91[.]23. Jingle Thief also reuses distinctive domain and URL structures across campaigns, further supporting attribution to a Morocco-based threat group.

“The Jingle Thief campaign demonstrates a clear focus on major retailers’ gift-card issuance systems,” Unit 42 concluded. “Gift-card systems are often under-monitored and widely accessible internally, making them an attractive extension to identity-based attacks.”

The activity was identified through behavioral anomalies detected by Cortex User Entity Behavior Analytics (UEBA) and Identity Threat Detection and Response (ITDR). Customers are better protected from this activity with the new Cortex Advanced Email Security module.

The researchers stressed that by understanding these tactics, defenders can better prioritize identity-based monitoring as the industry shifts toward treating identity as the new security perimeter. Understanding user behavior, login patterns and identity misuse are increasingly essential for early detection and response.

Tags: cybercrimes in moroccoCybersecurityMoroccan hackers
TweetShareShareSendShareScan

Recent News

Bayern Munich coach Vincent Kompany has confirmed that Moroccan international Ismael Saibari will feature against Borussia Dortmund in Saturday’s German Super Cup.

Kompany Confirms Ismael Saibari Will Play Against Borussia Dortmund

August 21, 2026
The second phase of the Marhaba 2026 operation approaches its busiest stretch before the end of August.

Tanger Med Warns Travelers of Late-August Peak in Marhaba 2026 Return Phase

August 21, 2026
FIFA has imposed heavy disciplinary sanctions on Argentina and several players involved in the confrontation that followed the 2026 FIFA World Cup final between Argentina and Spain.

FIFA Hands Paredes 10-Match Ban, Molina Seven After World Cup Final Clash

August 21, 2026
The shooting took place shortly after 4:30 p.m. on Sunday, August 16, at the Santo Stefano hospital.

Italian Officer Faces Attempted Murder Probe After Shooting Moroccan in Prato Hospital

August 21, 2026
Guinea Announces Bid to Host AFCON 2032 or 2036

Guinea Announces Bid to Host AFCON 2032 or 2036

August 21, 2026

USEFUL LINKS

  • About
  • Privacy Policy
  • Contact
  • Careers
  • Terms Of Use
  • Cookies Policy

TOPICS

  • Mawazine 2025
  • Environment
  • Politics
  • Lifestyle
  • Sports
  • Western Sahara

REGIONS

  • International
  • Maghreb
  • Middle East
  • Africa

Download our App


Download the Morocco World News app on Google Play for Android

Download the Morocco World News app on the Apple App Store for iPhone and iPad

Copyright 2026 Morocco World News. All rights reserved. Morocco World News is not responsible for the content of external sites.
Read about our approach to external linking.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • Login
No Result
View All Result
  • Home
  • Culture
  • Politics
  • Society
  • Economy
  • Opinion
  • Education
  • Sustainability
  • Tech
  • Sport
  • World Cup 2026

Useful Links

  • Prayer Times

Useful Links:

  • Prayer Times

All Right Reserved © 2026 Morocco World News .

Contact us
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?