Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors LAPSUS$

Also known as: DEV-0537, Strawberry Tempest, LAPSUS$, SLIPPY SPIDER, UNC3661, Lapsus

Description

LAPSUS$ is cyber criminal threat group that has been active since at least mid-2021. LAPSUS$ specializes in large-scale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.(Citation: BBC LAPSUS Apr 2022)(Citation: MSTIC DEV-0537 Mar 2022)(Citation: UNIT 42 LAPSUS Mar 2022)

AI Analysis

· 1 week ago

Executive Summary

LAPSUS$ is a cybercriminal threat group known for large-scale social engineering and extortion operations. The group has targeted various sectors globally, including government, manufacturing, education, energy, healthcare, technology, telecommunications, and media. LAPSUS$ operates with high sophistication, leveraging advanced tactics such as data destruction and credential theft to achieve its goals.

Goals & Targeting

LAPSUS$'s primary motivation appears to be financial gain, leveraging extortion and destructive attacks to coerce organizations into paying ransoms or complying with demands. The group targets sectors with significant data sensitivity and potential for disruption, such as government and healthcare, to maximize the impact of their attacks. Their victims include both private corporations and public institutions, indicating a broad targeting strategy aimed at maximizing opportunities for extortion.

Enhanced Description

LAPSUS$, also known as DEV-0537 or Strawberry Tempest, is a cybercriminal group that emerged in mid-2021. The group specializes in social engineering and extortion, often conducting destructive attacks without the use of ransomware. Their operations have impacted organizations across multiple sectors, including government agencies, healthcare providers, and financial institutions. LAPSUS$ has demonstrated a high level of operational sophistication, employing techniques such as credential theft, data destruction, and lateral movement within networks. The group's targeting profile suggests a focus on maximizing impact through high-profile victims, potentially to gain notoriety or financial benefits.

Key Capabilities

  • Advanced social engineering
  • Destructive attack techniques
  • Credential theft
  • Extortion tactics
  • Data destruction operations

MITRE ATT&CK Tactics

Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact

ATT&CK Techniques

T1087.002
T1597.002
T1213.002
T1133
T1489
T1069.002
T1555.005
T1005
T1586.002
T1598.004
T1578.003
T1588.001
T1068
T1584.002
T1213.001
T1111
T1003.003
T1078.004
T1003.006
T1213.005
T1090
T1552.008
T1136.003
T1078
T1531
T1589.001
T1684.001
T1485

Campaigns & Victims

LAPSUS$ has been involved in numerous high-profile campaigns, targeting entities such as AXCELA IO, AstraZeneca, and other major organizations. The group's operations often involve initial attacks to gain access to systems, followed by lateral movement and data exfiltration or destruction. Notable campaigns include attacks on government ministries, healthcare providers, and financial institutions, highlighting their ability to adapt tactics across different sectors.

IOC Patterns

  • Leverage social engineering techniques
  • Use of credential theft
  • Destructive attacks without ransomware
  • Targeted data exfiltration
  • Lateral movement within networks

Recommended Actions

  • Implement robust MFA solutions to mitigate T1621 and T1136.
  • Monitor for异常活动 in cloud accounts (T1078) and SharePoint services (T1213.002).
  • Secure credential storage to prevent T1555.005 and T1589 tactics.
  • Conduct regular security audits and patch management to address potential exploitation vectors (T1068).
  • Enhance network monitoring for signs of lateral movement and data exfiltration.

Suggested Tags

APT
extortion
ransomware
espionage
finance-sector

Confidence Assessment

High confidence in LAPSUS$'s operational capabilities, targeting profile, and associated techniques. However, specific details about their primary motivation and exact tools remain unclear due to limited public disclosure from the group.

ATT&CK Techniques

Collection
6 techniques
Credential Access
7 techniques
Reconnaissance
8 techniques
Resource Development
5 techniques

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

References

  1. BBC LAPSUS Apr 2022 — BBC. (2022, April 1). LAPSUS: Two UK Teenagers Charged with Hacking for Gang. Retrieved June 9, 2022.
  2. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  3. MSTIC DEV-0537 Mar 2022 — MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.
  4. UNIT 42 LAPSUS Mar 2022 — UNIT 42. (2022, March 24). Threat Brief: Lapsus$ Group. Retrieved May 17, 2022.

Intel Summary

43

Techniques

0

Tools

21

Campaigns

1

IOCs

0

Observed Data

13

Tactics

Tags

Ransomware
Healthcare Targeting
Government Targeting
APT
extortion
ransomware
espionage
finance-sector

Details

MITRE ID
G1004
Type
Unknown
Confidence
90%
First Seen
Dec 10, 2021
Last Seen
Jun 23, 2026
Added
May 2, 2026
STIX ID
intrusion-set--d8bc9788-4f7d-41a9-9e9d-ee1ea18a8cf7
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.