LAPSUS$
Aliases: DEV-0537, Strawberry Tempest
LAPSUS$ is cyber criminal threat group that has been active since at least mid-2021. LAPSUS$ specializes in large-scale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.
Open interactive actor investigation
ATT&CK techniques
T1589
Gather Victim Identity InformationT1005
Data from Local SystemT1069.002
Domain GroupsT1213.001
ConfluenceT1588.002
ToolT1485
Data DestructionT1213.003
Code RepositoriesT1213.002
SharepointT1583.003
Virtual Private ServerT1591.004
Identify RolesT1090
ProxyT1087.002
Domain AccountT1133
External Remote ServicesT1078
Valid AccountsT1656
ImpersonationT1588.001
MalwareT1598.004
Spearphishing VoiceT1204
User ExecutionT1552.008
Chat MessagesT1489
Service StopT1593.003
Code RepositoriesT1136.003
Cloud AccountT1114.003
Email Forwarding RuleT1591.002
Business RelationshipsT1578.003
Delete Cloud InstanceT1555.003
Credentials from Web BrowsersT1531
Account Access RemovalT1589.001
CredentialsT1068
Exploitation for Privilege EscalationT1621
Multi-Factor Authentication Request GenerationT1098.003
Additional Cloud RolesT1003.006
DCSyncT1586.002
Email AccountsT1213.005
Messaging ApplicationsT1589.002
Email AddressesT1584.002
DNS ServerT1003.003
NTDST1555.005
Password ManagersT1199
Trusted RelationshipT1597.002
Purchase Technical DataT1578.002
Create Cloud InstanceT1078.004
Cloud AccountsT1111
Multi-Factor Authentication Interception
Gather Victim Identity InformationT1005
Data from Local SystemT1069.002
Domain GroupsT1213.001
ConfluenceT1588.002
ToolT1485
Data DestructionT1213.003
Code RepositoriesT1213.002
SharepointT1583.003
Virtual Private ServerT1591.004
Identify RolesT1090
ProxyT1087.002
Domain AccountT1133
External Remote ServicesT1078
Valid AccountsT1656
ImpersonationT1588.001
MalwareT1598.004
Spearphishing VoiceT1204
User ExecutionT1552.008
Chat MessagesT1489
Service StopT1593.003
Code RepositoriesT1136.003
Cloud AccountT1114.003
Email Forwarding RuleT1591.002
Business RelationshipsT1578.003
Delete Cloud InstanceT1555.003
Credentials from Web BrowsersT1531
Account Access RemovalT1589.001
CredentialsT1068
Exploitation for Privilege EscalationT1621
Multi-Factor Authentication Request GenerationT1098.003
Additional Cloud RolesT1003.006
DCSyncT1586.002
Email AccountsT1213.005
Messaging ApplicationsT1589.002
Email AddressesT1584.002
DNS ServerT1003.003
NTDST1555.005
Password ManagersT1199
Trusted RelationshipT1597.002
Purchase Technical DataT1578.002
Create Cloud InstanceT1078.004
Cloud AccountsT1111
Multi-Factor Authentication Interception