Skip to content

LAPSUS$

LAPSUS$ is a financially motivated cybercrime and extortion group best known for high-profile intrusions against major technology, telecommunications, gaming, identity, and enterprise software organizations.

Profile source: Mallory opens in a new tab

LAPSUS$

Family profile

LAPSUS$ is a financially motivated cybercrime and extortion group best known for high-profile intrusions against major technology, telecommunications, gaming, identity, and enterprise software organizations. The group is widely associated with a loose, youth-driven criminal ecosystem and has been linked by multiple defenders and law-enforcement reporting to The Com. Common aliases include DEV-0537, Slippy Spider, Strawberry Tempest, Lapsus, Lapsus Group, and LAPSUS$ Group.

LAPSUS$ became notable for aggressive public extortion, data theft, and intrusion-and-leak operations rather than conventional ransomware deployment. The group has been linked to attacks affecting organizations including Nvidia, Microsoft, Samsung, Ubisoft, Okta, Rockstar Games, BT/EE, and Globant, and has also been associated with later victim claims involving additional enterprises and financial-sector organizations. Some newer victim claims remain unconfirmed and should be treated cautiously.

The actor is strongly associated with social engineering-centric tradecraft. Reported techniques include vishing, help-desk impersonation, credential theft, abuse of authentication and identity workflows, insider recruitment or bribery, and privilege escalation after initial access. LAPSUS$ operations have repeatedly demonstrated a focus on identity providers, source code repositories, internal collaboration platforms, cloud-hosted data, and other high-value corporate systems that enable both intelligence collection and extortion leverage. Public reporting has also linked the group to exploitation for privilege escalation and setuid/setgid abuse in some intrusion chains.

Operationally, LAPSUS$ has favored rapid smash-and-grab intrusions, theft of sensitive internal data, and public pressure through leak channels and sale offers. The group has repeatedly advertised stolen source code, internal documents, customer data, and infrastructure information, and has used public messaging platforms and criminal forums to pressure victims, attract attention, and monetize access. In some cases, LAPSUS$ has collaborated or been observed in proximity with other criminal actors, including TeamPCP and broader Com-affiliated clusters, though such relationships appear opportunistic rather than indicative of a rigid hierarchy.

Several individuals publicly tied to LAPSUS$ have been arrested and convicted in the United Kingdom, reinforcing assessments that the group has included English-speaking members and overlaps with other socially engineered intrusion crews. Arion Kurtaj has been linked to LAPSUS$ in connection with the Rockstar Games intrusion and other major breaches, and Thalha Jubair has been reported as linked to both LAPSUS$ and The Com. These cases underscore the group’s association with young operators conducting high-impact intrusions against globally recognized targets.

LAPSUS$ is best understood as a prominent extortion-focused intrusion collective whose hallmark is the compromise of large organizations through human-centric access operations, followed by theft and public weaponization of sensitive data. Its significance lies less in bespoke malware than in effective social engineering, identity compromise, and the ability to translate unauthorized access into outsized reputational and financial pressure on victims.

Operational record

1
Indicators
1
YARA rules
4
Leak sites
0 available

Credential Theft

  • Mimikatz

Discovery Enum

  • ADExplorer

LOLBAS

  • NTDS Utility (ntdsutil)

RMM Tools

  • AnyDesk

Published indicators

Sha256

1 total
  • bdcb86e57332cc0b98c9f86456c4d014f6cf9ff96c21287af25046dc9dff8fa5

MITRE ATT&CK

LAPSUS$ in ATT&CK

112 distinct techniques

Techniques

112 techniques
T1213 Data from Information Repositories T1041 Exfiltration Over C2 Channel T1486 Data Encrypted for Impact T1657 Financial Theft T1656 Impersonation T1537 Transfer Data to Cloud Account T1078 Valid Accounts T1565 Data Manipulation T1074 Data Staged T1567 Exfiltration Over Web Service T1190 Exploit Public-Facing Application T1567.002 Exfiltration to Cloud Storage T1598.004 Spearphishing Voice T1068 Exploitation for Privilege Escalation T1059 Command and Scripting Interpreter T1005 Data from Local System T1018 Remote System Discovery T1588.001 Malware T1087.002 Domain Account T1070.004 File Deletion T1003.006 DCSync T1566 Phishing T1078.004 Cloud Accounts T1553.002 Code Signing T1649 Steal or Forge Authentication Certificates T1048 Exfiltration Over Alternative Protocol T1598 Phishing for Information T1621 Multi-Factor Authentication Request Generation T1204.002 Malicious File T1014 Rootkit T1189 Drive-by Compromise T1557 Adversary-in-the-Middle T1555 Credentials from Password Stores T1593 Search Open Websites/Domains T1087 Account Discovery T1133 External Remote Services T1588.002 Tool T1114.003 Email Forwarding Rule T1485 Data Destruction T1651 Cloud Administration Command T1562 Impair Defenses T1555.003 Credentials from Web Browsers T1199 Trusted Relationship T1552.001 Credentials In Files T1567.003 Exfiltration to Text Storage Sites T1589 Gather Victim Identity Information T1583.003 Virtual Private Server T1098 Account Manipulation T1498 Network Denial of Service T1195 Supply Chain Compromise T1021 Remote Services T1586 Compromise Accounts T1539 Steal Web Session Cookie T1491.001 Internal Defacement T1489 Service Stop T1491 Defacement T1003 OS Credential Dumping T1056 Input Capture T1574 Hijack Execution Flow T1119 Automated Collection T1565.001 Stored Data Manipulation T1528 Steal Application Access Token T1583 Acquire Infrastructure T1090 Proxy T1129 Shared Modules T1136 Create Account T1203 Exploitation for Client Execution T1195.001 Compromise Software Dependencies and Development Tools T1580 Cloud Infrastructure Discovery T1020 Automated Exfiltration T1213.003 Code Repositories T1566.004 Spearphishing Voice T1036 Masquerading T1530 Data from Cloud Storage T1030 Data Transfer Size Limits T1567.001 Exfiltration to Code Repository T1526 Cloud Service Discovery T1552 Unsecured Credentials T1560 Archive Collected Data T1090.001 Internal Proxy T1021.001 Remote Desktop Protocol T1021.005 VNC T1003.003 NTDS T1090.002 External Proxy T1102 Web Service T1505.003 Web Shell T1098.005 Device Registration T1069.001 Local Groups T1136.003 Cloud Account T1098.003 Additional Cloud Roles T1070.008 Clear Mailbox Data T1586.003 Cloud Accounts T1531 Account Access Removal T1069.002 Domain Groups T1204 User Execution T1684.001 Social Engineering: Impersonation T1111 Multi-Factor Authentication Interception T1552.008 Unsecured Credentials: Chat Messages T1555.005 Credentials from Password Stores: Password Managers T1213.001 Data from Information Repositories: Confluence T1213.002 Data from Information Repositories: Sharepoint T1213.005 Data from Information Repositories: Messaging Applications T1584.002 Compromise Infrastructure: DNS Server T1586.002 Compromise Accounts: Email Accounts T1589.001 Gather Victim Identity Information: Credentials T1589.002 Gather Victim Identity Information: Email Addresses T1591.002 Gather Victim Org Information: Business Relationships T1591.004 Gather Victim Org Information: Identify Roles T1593.003 Search Open Websites/Domains: Code Repositories T1597.002 Search Closed Sources: Purchase Technical Data T1578.002 Modify Cloud Compute Infrastructure: Create Cloud Instance T1578.003 Modify Cloud Compute Infrastructure: Delete Cloud Instance

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.