Credential Theft
- Mimikatz
LAPSUS$ is a financially motivated cybercrime and extortion group best known for high-profile intrusions against major technology, telecommunications, gaming, identity, and enterprise software organizations.
Profile source: Mallory opens in a new tabLAPSUS$
LAPSUS$ is a financially motivated cybercrime and extortion group best known for high-profile intrusions against major technology, telecommunications, gaming, identity, and enterprise software organizations. The group is widely associated with a loose, youth-driven criminal ecosystem and has been linked by multiple defenders and law-enforcement reporting to The Com. Common aliases include DEV-0537, Slippy Spider, Strawberry Tempest, Lapsus, Lapsus Group, and LAPSUS$ Group.
LAPSUS$ became notable for aggressive public extortion, data theft, and intrusion-and-leak operations rather than conventional ransomware deployment. The group has been linked to attacks affecting organizations including Nvidia, Microsoft, Samsung, Ubisoft, Okta, Rockstar Games, BT/EE, and Globant, and has also been associated with later victim claims involving additional enterprises and financial-sector organizations. Some newer victim claims remain unconfirmed and should be treated cautiously.
The actor is strongly associated with social engineering-centric tradecraft. Reported techniques include vishing, help-desk impersonation, credential theft, abuse of authentication and identity workflows, insider recruitment or bribery, and privilege escalation after initial access. LAPSUS$ operations have repeatedly demonstrated a focus on identity providers, source code repositories, internal collaboration platforms, cloud-hosted data, and other high-value corporate systems that enable both intelligence collection and extortion leverage. Public reporting has also linked the group to exploitation for privilege escalation and setuid/setgid abuse in some intrusion chains.
Operationally, LAPSUS$ has favored rapid smash-and-grab intrusions, theft of sensitive internal data, and public pressure through leak channels and sale offers. The group has repeatedly advertised stolen source code, internal documents, customer data, and infrastructure information, and has used public messaging platforms and criminal forums to pressure victims, attract attention, and monetize access. In some cases, LAPSUS$ has collaborated or been observed in proximity with other criminal actors, including TeamPCP and broader Com-affiliated clusters, though such relationships appear opportunistic rather than indicative of a rigid hierarchy.
Several individuals publicly tied to LAPSUS$ have been arrested and convicted in the United Kingdom, reinforcing assessments that the group has included English-speaking members and overlaps with other socially engineered intrusion crews. Arion Kurtaj has been linked to LAPSUS$ in connection with the Rockstar Games intrusion and other major breaches, and Thalha Jubair has been reported as linked to both LAPSUS$ and The Com. These cases underscore the group’s association with young operators conducting high-impact intrusions against globally recognized targets.
LAPSUS$ is best understood as a prominent extortion-focused intrusion collective whose hallmark is the compromise of large organizations through human-centric access operations, followed by theft and public weaponization of sensitive data. Its significance lies less in bespoke malware than in effective social engineering, identity compromise, and the ability to translate unauthorized access into outsized reputational and financial pressure on victims.
bdcb86e57332cc0b98c9f86456c4d014f6cf9ff96c21287af25046dc9dff8fa5MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.