LAPSUS$

MITRE ATT&CK: G1004 View on attack.mitre.org

Aliases: DEV-0537, Strawberry Tempest, LAPSUS$, SLIPPY SPIDER, UNC3661, Lapsus

First seen
2021-06-01 00:00:00
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
team
Actor type
criminal
Profile updated
2026-07-07 12:34:26

Targeted industries: government-and-public-sector manufacturing education-and-nonprofits energy-and-utilities healthcare-and-pharmaceutical technology-and-telecommunications media-and-entertainment

Context

LAPSUS$ is cyber criminal threat group that has been active since at least mid-2021. LAPSUS$ specializes in large-scale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.

Detection coverage

  • 7 YARA rules
  • 325 Sigma rules

Malware & tools used

  • Gather Victim Identity Information (attack-pattern)
  • Data from Local System (attack-pattern)
  • Domain Groups (attack-pattern)
  • Confluence (attack-pattern)
  • Tool (attack-pattern)
  • Data Destruction (attack-pattern)
  • Code Repositories (attack-pattern)
  • Sharepoint (attack-pattern)
  • Virtual Private Server (attack-pattern)
  • Identify Roles (attack-pattern)
  • Proxy (attack-pattern)
  • Domain Account (attack-pattern)
  • External Remote Services (attack-pattern)
  • Valid Accounts (attack-pattern)
  • Malware (attack-pattern)
  • Spearphishing Voice (attack-pattern)
  • User Execution (attack-pattern)
  • Chat Messages (attack-pattern)
  • Service Stop (attack-pattern)
  • Code Repositories (attack-pattern)
  • Cloud Account (attack-pattern)
  • Email Forwarding Rule (attack-pattern)
  • Business Relationships (attack-pattern)
  • Delete Cloud Instance (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)

Reports & references

  • Microsoft — Dev 0537 Criminal Actor Targeting Organizations For Data Exfiltration And Destruction (report)
  • blog.checkpoint.com — Lapsus Ransomware Gang Uses Stolen Source Code To Disguise Malware Files As Trustworthy Check Point Customers Remain Protected (report)
  • CrowdStrike — Slippy Spider (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)
  • MITRE ATT&CK — G1004 (report)
  • Palo Alto Unit 42 — Lapsus Group (report)
  • bbc.com — Technology 60953527 (report)

External references