Breaking 17:30 Mexico sends over 800 tons of humanitarian aid to Cuba amid economic crisis 17:20 Saudi oil exports to China set for multi year high in March 17:00 Moroccan citizens rank second worldwide for French visas in 2025 16:50 World Monuments Fund commits $7 million to global heritage sites 16:45 Sabri Al-Hou to "Walaw": Madrid meeting gives strong momentum to resolve Moroccan Sahara dispute 16:30 Three dead and four missing after migrant boat sinks off Turkey 16:20 EU identifies two training sites in Ukraine for troop instruction 16:12 Real Madrid and UEFA reach deal to end Super League dispute 16:00 Lufthansa cancels 800 flights in Germany amid nationwide strike 15:50 Nissan forecasts $4.2 billion annual loss amid restructuring 15:41 Epstein document release triggers resignations across Europe 15:30 Morocco named 2025 Partner Destination of the Year by France’s SETO 15:20 Ukraine halts Russian oil transit after Druzhba pipeline strike 15:00 European commission offices searched in probe over real estate asset sale 14:50 Russian war losses outpace recruitment for first time in January 14:31 Morocco shines with five stadiums nominated for Global “Stadium of the Year” award 14:30 French tourist reported missing in northeastern Chad 14:20 Russia pledges oil aid to Cuba amid tourist evacuation 14:00 Norwegian police search homes of former prime minister in Epstein-linked probe 13:50 Moroccan households navigate rising costs ahead of Ramadan 2026 13:30 Storm Nils leaves one dead and 850,000 homes without power in France 13:20 Microbes extract platinum metals from meteorites in space station test 13:12 Royal directives launch $3 billion relief program for flood-affected families in Morocco 13:00 After the Greenland saga, NATO moves to prevent another crisis 12:50 Goldman Sachs warns of new era of high commodity volatility 12:45 Bulgarian Central Bank deputy governor appointed to lead caretaker government 12:30 Argentina senate approves controversial labor reform by President Milei 12:20 Modified herpes virus boosts immune attack against deadly brain cancer 12:15 Pressure mounts on Dubai’s DP World amid Epstein document revelations 12:03 Love Brand | Abujad Sara Among the Favorite Influencers in 2025 12:00 United Kingdom pledges over £500 million in aid to strengthen Ukraine’s defense 11:50 German researchers develop AI to predict liquid properties 11:45 China lowers anti-subsidy tariffs on European dairy imports 11:30 Sudan boat capsizes on Nile, at least 21 dead 11:25 Love Brand | Bimo Among Consumers’ Favorites In 2025 11:20 US energy secretary pledges dramatic rise in Venezuela oil output 11:00 Aliyev hails US-Azerbaijan strategic partnership charter as ‘historic’ milestone 10:50 Ukraine tests low cost Sunray laser to shoot down drones 10:30 CAC 40 surpasses 8 400 points for first time on strong corporate earnings 10:20 Nioh 3 sells 700,000 copies in four days 10:00 Yango Ride launches global “Yango Cares” initiative to support drivers beyond the road 10:00 Food safety alert: Exposure to cadmium, mercury and lead remains concerning in France, says Anses 09:50 Mercedes-Benz profits plunge 57 percent in 2025 amid tariffs and China slowdown 09:50 Greenland Olympian warns climate change threatens winter sports 09:30 Hermès CEO Axel Dumas says Jeffrey Epstein pushed for meeting in 2013 09:20 Musk restructures xAI into four divisions amid cofounder departures 09:10 “Dams played a decisive role in containing the floods,” says Mokhtar Bzioui 09:00 Multiple rescues as flash flooding inundates Alice Springs after severe storms 08:50 Ukraine warns of nuclear disaster risk at Zaporizhzhia plant 08:33 Marjane opens 44th hypermarket in Ouarzazate as part of national expansion strategy 08:30 Saudi Arabia signs major Gökbey helicopter joint production agreement 08:20 Italy and Germany challenge France influence ahead of EU summit 08:00 Italy declines to join Trump’s board of peace citing constitutional constraints 07:50 Wrexham sells minority stake to Apollo Sports Capital 07:40 Canada school shooting: Investigators examine profile of 18-year-old suspect 07:20 Venezuela moves toward adopting historic amnesty law amid political tensions 07:00 North Korea: Kim Jong Un’s daughter reportedly poised as potential successor 18:50 France expands humanitarian visas for Iranians fleeing crackdown 18:30 Third infant death reported in France amid baby formula recall 18:20 Daniel Ek steps down as Spotify CEO after final earnings call 18:00 Meta prepares Instants app to rival Snapchat with ephemeral media 17:50 Sanctioned oil tankers shift to Russian flag amid Western seizures

Moroccan cybercriminals exploit global retail firms in gift card scheme

Tuesday 28 October 2025 - 12:20
By: Dakir Madiha
Moroccan cybercriminals exploit global retail firms in gift card scheme

A sophisticated cybercrime campaign originating in Morocco has been targeting global retail and consumer services companies, stealing and monetizing gift cards on a large scale. Dubbed “Jingle Thief,” this operation has been active since 2021, leveraging cloud-based infrastructure to execute fraud, particularly during major holiday seasons when gift card activity peaks.

Extensive infiltration and prolonged access

According to Unit 42, the cybersecurity division of Palo Alto Networks, the attackers infiltrate organizations through phishing and SMS-based “smishing” campaigns. They exploit Microsoft 365 services such as SharePoint, OneDrive, Exchange, and Entra ID to gain access to sensitive systems. Once inside, they maintain access for extended periods, sometimes over a year, allowing them to compromise multiple user accounts and execute large-scale fraud.

In one incident, attackers retained access for ten months, compromising over 60 user accounts within a single global enterprise. Their activities spike during holiday periods, coinciding with reduced staffing and increased gift card purchases, making detection more challenging.

Sophisticated phishing tactics

The attackers craft highly convincing phishing content tailored to their targets. By mimicking organizational branding, portals, and email templates, they create authentic-looking login pages designed to steal credentials. Some phishing lures impersonate nonprofits or NGOs to increase credibility.

Phishing URLs often appear legitimate but redirect victims to malicious sites. For example, attackers use deceptive URL formatting, such as embedding malicious domains within trusted-looking structures, to obscure their true origin.

To evade detection, the attackers employ compromised WordPress servers to deliver phishing emails using self-hosted PHP mailer scripts. They also use advanced techniques to avoid forensic traces, such as minimizing logs and using VPNs with abnormal configurations.

Why gift cards are the prime target

Gift cards are particularly attractive to cybercriminals due to their ease of redemption, anonymity, and minimal personal information requirements. Once stolen, the cards are resold on gray-market platforms at discounted rates, providing quick cash flow. Retail environments are especially vulnerable, as gift card systems are often accessible to a wide range of internal users and support multiple vendors, creating broader attack surfaces.

Evidence links attackers to Morocco

The investigation identified multiple IP addresses geolocated to Morocco, including 105.156.109[.]227 and 196.89.141[.]80. The attackers also used Moroccan ASN organizations such as MT-MPLS and MAROCCONNECT. Some US-based infrastructure was also employed, potentially as proxies or compromised hosts.

The activity cluster, tracked as CL-CRI-1032, overlaps with threat actors known as Atlas Lion and STORM-0539. Jingle Thief’s reuse of distinctive domain structures across campaigns further supports its attribution to Moroccan-based groups.

Strengthening defenses against identity-based attacks

Unit 42 emphasized the importance of prioritizing identity-based monitoring as part of modern cybersecurity strategies. Behavioral anomalies, such as suspicious login patterns and identity misuse, were key indicators of the Jingle Thief campaign. Advanced tools like Cortex User Entity Behavior Analytics (UEBA) and Identity Threat Detection and Response (ITDR) have helped detect such anomalies.

As identity becomes the new perimeter in cybersecurity, organizations are urged to enhance their monitoring of user behavior and identity misuse to detect and respond to threats early. Retailers, in particular, must strengthen oversight of gift card systems to mitigate vulnerabilities exploited by campaigns like Jingle Thief.


  • Fajr
  • Sunrise
  • Dhuhr
  • Asr
  • Maghrib
  • Isha

Read more

This website, walaw.press, uses cookies to provide you with a good browsing experience and to continuously improve our services. By continuing to browse this site, you agree to the use of these cookies.