Storm-0539 is a financially motivated threat actor targeting retailers with gift card fraud using phishing and MFA bypass.
Analyst brief
Storm-0539 is a financially motivated threat actor active since at least 2021, targeting retail organizations for gift card fraud. They use phishing emails and SMS to steal credentials and session tokens, then register devices to bypass MFA and maintain persistence. Key TTPs include targeted phishing, session hijacking, MFA bypass, and internal reconnaissance. Defenders should focus on detecting anomalous MFA prompts, token theft, and unauthorized mailbox or network configuration access.
Storm-0539
unknown
Storm-0539 is a financially motivated threat actor that has been active since at least 2021. They primarily target retail organizations for gift card fraud and theft. Their tactics include phishing via emails or SMS to distribute malicious links that redirect users to phishing pages designed to steal credentials and session tokens. Once access is gained, Storm-0539 registers a device for secondary authentication prompts, bypassing multi-factor authentication and gaining persistence in the environment. They also collect emails, contact lists, and network configurations for further attacks against the same organizations.