LAPSUS$
[LAPSUS$](https://attack.mitre.org/groups/G1004) is cyber criminal threat group that has been active since at least mid-2021. [LAPSUS$](https://attack.mitre.org/groups/G1004) specializes in large-scale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.(Citation: BBC LAPSUS Apr 2022)(Citation: MSTIC DEV-0537 Mar 2022)(Citation: UNIT 42 LAPSUS Mar 2022)
Properties
- stix_id
- intrusion-set--d8bc9788-4f7d-41a9-9e9d-ee1ea18a8cf7
- signal_observed_at
- 2026-09-11T17:55:00+00:00
- type
- intrusion-set
MITRE ATT&CK Techniques (44)
Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be
An adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant. For example,
Adversaries may gather information about the victim's business relationships that can be used during targeting. Information about an organization’s bu
Adversaries may directly collect unsecured credentials stored or passed through user communication services. Credentials may be sent and stored in use
Adversaries may create a cloud account to maintain access to victim systems. With a sufficient level of access, such accounts may be used to establish
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense
Adversaries may leverage code repositories to collect valuable information. Code repositories are tools/services that store source code and automate s
Adversaries may search public code repositories for information about victims that can be used during targeting. Victims may store code in repositorie
Adversaries may leverage Confluence repositories to mine valuable information. Often found in development environments alongside Atlassian JIRA, Conf
An adversary may create a new instance or virtual machine (VM) within the compute service of a cloud account to evade defenses. Creating a new instanc
Adversaries may gather credentials that can be used during targeting. Account credentials gathered by adversaries may be those directly associated wit
Adversaries may acquire credentials from web browsers by reading files specific to the target browser.(Citation: Talos Olympic Destroyer 2018) Web bro
Adversaries may attempt to access credentials and other sensitive information by abusing a Windows Domain Controller's application programming interfa
Adversaries may compromise third-party DNS servers that can be used during targeting. During post-compromise activity, adversaries may utilize DNS tra
Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and networ
Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to
An adversary may delete a cloud instance after they have performed malicious activities in an attempt to evade detection and remove evidence of their
Adversaries may attempt to get a listing of domain accounts. This information can help adversaries determine which domain accounts exist to aid in fol
Adversaries may attempt to find domain-level groups and permission settings. The knowledge of domain-level permission groups can help adversaries dete
Adversaries may compromise email accounts that can be used during targeting. Adversaries can use compromised email accounts to further their operation
Adversaries may gather email addresses that can be used during targeting. Even if internal instances exist, organizations may have public-facing email
Adversaries may setup email forwarding rules to collect sensitive information. Adversaries may abuse email forwarding rules to monitor the activities
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversar
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, an
Adversaries may gather information about the victim's identity that can be used during targeting. Information about identities may include a variety o
Adversaries may gather information about identities and roles within the victim organization that can be used during targeting. Information about busi
Adversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf. For
Adversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf. For
Adversaries may buy, steal, or download malware that can be used during targeting. Malicious software can include payloads, droppers, post-compromise
Adversaries may leverage chat and messaging applications, such as Microsoft Teams, Google Chat, and Slack, to mine valuable information. The follow
Software & Tools (2)
[Mimikatz](https://attack.mitre.org/software/S0002) is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along
[Mimikatz](https://attack.mitre.org/software/S0002) is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along
Explore this actor's full graph with Ninja Signal