Also known as: DEV-0537, Strawberry Tempest, LAPSUS$, SLIPPY SPIDER, UNC3661, Lapsus
LAPSUS$ is cyber criminal threat group that has been active since at least mid-2021. LAPSUS$ specializes in large-scale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.(Citation: BBC LAPSUS Apr 2022)(Citation: MSTIC DEV-0537 Mar 2022)(Citation: UNIT 42 LAPSUS Mar 2022)
Executive Summary
LAPSUS$ is a cybercriminal threat group known for large-scale social engineering and extortion operations. The group has targeted various sectors globally, including government, manufacturing, education, energy, healthcare, technology, telecommunications, and media. LAPSUS$ operates with high sophistication, leveraging advanced tactics such as data destruction and credential theft to achieve its goals.
Goals & Targeting
LAPSUS$'s primary motivation appears to be financial gain, leveraging extortion and destructive attacks to coerce organizations into paying ransoms or complying with demands. The group targets sectors with significant data sensitivity and potential for disruption, such as government and healthcare, to maximize the impact of their attacks. Their victims include both private corporations and public institutions, indicating a broad targeting strategy aimed at maximizing opportunities for extortion.
Enhanced Description
LAPSUS$, also known as DEV-0537 or Strawberry Tempest, is a cybercriminal group that emerged in mid-2021. The group specializes in social engineering and extortion, often conducting destructive attacks without the use of ransomware. Their operations have impacted organizations across multiple sectors, including government agencies, healthcare providers, and financial institutions. LAPSUS$ has demonstrated a high level of operational sophistication, employing techniques such as credential theft, data destruction, and lateral movement within networks. The group's targeting profile suggests a focus on maximizing impact through high-profile victims, potentially to gain notoriety or financial benefits.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Campaigns & Victims
LAPSUS$ has been involved in numerous high-profile campaigns, targeting entities such as AXCELA IO, AstraZeneca, and other major organizations. The group's operations often involve initial attacks to gain access to systems, followed by lateral movement and data exfiltration or destruction. Notable campaigns include attacks on government ministries, healthcare providers, and financial institutions, highlighting their ability to adapt tactics across different sectors.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in LAPSUS$'s operational capabilities, targeting profile, and associated techniques. However, specific details about their primary motivation and exact tools remain unclear due to limited public disclosure from the group.
No tools linked yet.
No observed data linked yet.
43
Techniques
0
Tools
21
Campaigns
1
IOCs
0
Observed Data
13
Tactics