LAPSUS$
MITRE ATT&CK: G1004 View on attack.mitre.org
Aliases: DEV-0537, Strawberry Tempest, LAPSUS$, SLIPPY SPIDER, UNC3661, Lapsus
- First seen
- 2021-06-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- intermediate
- Resource level
- team
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:34:26
Targeted industries: government-and-public-sector manufacturing education-and-nonprofits energy-and-utilities healthcare-and-pharmaceutical technology-and-telecommunications media-and-entertainment
Context
LAPSUS$ is cyber criminal threat group that has been active since at least mid-2021. LAPSUS$ specializes in large-scale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.
Detection coverage
- 7 YARA rules
- 325 Sigma rules
Malware & tools used
- Gather Victim Identity Information (attack-pattern)
- Data from Local System (attack-pattern)
- Domain Groups (attack-pattern)
- Confluence (attack-pattern)
- Tool (attack-pattern)
- Data Destruction (attack-pattern)
- Code Repositories (attack-pattern)
- Sharepoint (attack-pattern)
- Virtual Private Server (attack-pattern)
- Identify Roles (attack-pattern)
- Proxy (attack-pattern)
- Domain Account (attack-pattern)
- External Remote Services (attack-pattern)
- Valid Accounts (attack-pattern)
- Malware (attack-pattern)
- Spearphishing Voice (attack-pattern)
- User Execution (attack-pattern)
- Chat Messages (attack-pattern)
- Service Stop (attack-pattern)
- Code Repositories (attack-pattern)
- Cloud Account (attack-pattern)
- Email Forwarding Rule (attack-pattern)
- Business Relationships (attack-pattern)
- Delete Cloud Instance (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
Reports & references
- Microsoft — Dev 0537 Criminal Actor Targeting Organizations For Data Exfiltration And Destruction (report)
- blog.checkpoint.com — Lapsus Ransomware Gang Uses Stolen Source Code To Disguise Malware Files As Trustworthy Check Point Customers Remain Protected (report)
- CrowdStrike — Slippy Spider (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Microsoft — Microsoft Threat Actor Naming (report)
- MITRE ATT&CK — G1004 (report)
- Palo Alto Unit 42 — Lapsus Group (report)
- bbc.com — Technology 60953527 (report)