Group overview
Lapsus$ is an internationally composed data extortion group most active from mid-2021 through 2022, executing high-profile breaches against Microsoft, Nvidia, Samsung, Okta, and Uber by stealing source code and threatening leaks rather than encrypting files; several members β predominantly teenagers β were arrested in the UK.
Preferred targets
Financial Services Β· 2
Technology Β· 2
Consumer Services Β· 1
Telecommunication Β· 1
Business Services Β· 1
Most targeted countries
US Β· 3
MM Β· 1
SE Β· 1
DE Β· 1
ES Β· 1
Tactics & techniques (MITRE ATT&CK)
Initial Access
Valid Accounts
Valid Accounts: Cloud Accounts
External Remote Services
Trusted Relationship
Persistence
Valid Accounts
Valid Accounts: Cloud Accounts
Account Manipulation: Additional Cloud Roles
External Remote Services
Create Account: Cloud Account
Privilege Escalation
Exploitation for Privilege Escalation
Valid Accounts
Valid Accounts: Cloud Accounts
Account Manipulation: Additional Cloud Roles
Stealth
Valid Accounts
Valid Accounts: Cloud Accounts
Social Engineering: Impersonation
Credential Access
OS Credential Dumping: NTDS
OS Credential Dumping: DCSync
Multi-Factor Authentication Interception
Unsecured Credentials: Chat Messages
Credentials from Password Stores: Credentials from Web Browsers
Credentials from Password Stores: Password Managers
Multi-Factor Authentication Request Generation
Discovery
Permission Groups Discovery: Domain Groups
Account Discovery: Domain Account
Collection
Data from Local System
Email Collection: Email Forwarding Rule
Data from Information Repositories: Confluence
Data from Information Repositories: Sharepoint
Data from Information Repositories: Code Repositories
Data from Information Repositories: Messaging Applications