HackerFeeds
All ransomware groups

lapsus$

25 tracked victims
·first seen 2021-12-10·last activity 2026-06-23

Group profile

Lapsus$ is an internationally composed data extortion group most active from mid-2021 through 2022, executing high-profile breaches against Microsoft, Nvidia, Samsung, Okta, and Uber by stealing source code and threatening leaks rather than encrypting files; several members — predominantly teenagers — were arrested in the UK.

MITRE ATT&CK TTPs

TA0001

Initial Access

  • T1078Valid Accounts

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has used compromised credentials and/or session tokens to gain access into a victim's VPN, VDI, RDP, and IAMs.(Citation: MSTIC DEV-0537 Mar 2022)(Citation: NCC Group LAPSUS Apr 2022)

  • T1078.004Valid Accounts: Cloud Accounts

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has used compromised credentials to access cloud assets within a target organization.(Citation: MSTIC DEV-0537 Mar 2022)

  • T1133External Remote Services

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has gained access to internet-facing systems and applications, including virtual private network (VPN), remote desktop protocol (RDP), and virtual desktop infrastructure (VDI) including Citrix. (Citation: MSTIC DEV-0537 Mar 2022)(Citation: NCC Group LAPSUS Apr 2022)

  • T1199Trusted Relationship

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has accessed internet-facing identity providers such as Azure Active Directory and Okta to target specific organizations.(Citation: MSTIC DEV-0537 Mar 2022)

TA0002

Execution

  • T1204User Execution

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has recruited target organization employees or contractors who provide credentials and approve an associated MFA prompt, or install remote management software onto a corporate workstation, allowing [LAPSUS$](https://attack.mitre.org/groups/G1004) to take control of an authenticated system.(Citation: MSTIC DEV-0537 Mar 2022)

TA0003

Persistence

  • T1078Valid Accounts

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has used compromised credentials and/or session tokens to gain access into a victim's VPN, VDI, RDP, and IAMs.(Citation: MSTIC DEV-0537 Mar 2022)(Citation: NCC Group LAPSUS Apr 2022)

  • T1078.004Valid Accounts: Cloud Accounts

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has used compromised credentials to access cloud assets within a target organization.(Citation: MSTIC DEV-0537 Mar 2022)

  • T1098.003Account Manipulation: Additional Cloud Roles

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has added the global admin role to accounts they have created in the targeted organization's cloud instances.(Citation: MSTIC DEV-0537 Mar 2022)

  • T1133External Remote Services

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has gained access to internet-facing systems and applications, including virtual private network (VPN), remote desktop protocol (RDP), and virtual desktop infrastructure (VDI) including Citrix. (Citation: MSTIC DEV-0537 Mar 2022)(Citation: NCC Group LAPSUS Apr 2022)

  • T1136.003Create Account: Cloud Account

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has created global admin accounts in the targeted organization's cloud instances to gain persistence.(Citation: MSTIC DEV-0537 Mar 2022)

TA0004

Privilege Escalation

  • T1068Exploitation for Privilege Escalation

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has exploited unpatched vulnerabilities on internally accessible servers including JIRA, GitLab, and Confluence for privilege escalation.(Citation: MSTIC DEV-0537 Mar 2022)

  • T1078Valid Accounts

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has used compromised credentials and/or session tokens to gain access into a victim's VPN, VDI, RDP, and IAMs.(Citation: MSTIC DEV-0537 Mar 2022)(Citation: NCC Group LAPSUS Apr 2022)

  • T1078.004Valid Accounts: Cloud Accounts

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has used compromised credentials to access cloud assets within a target organization.(Citation: MSTIC DEV-0537 Mar 2022)

  • T1098.003Account Manipulation: Additional Cloud Roles

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has added the global admin role to accounts they have created in the targeted organization's cloud instances.(Citation: MSTIC DEV-0537 Mar 2022)

TA0005

Stealth

  • T1078Valid Accounts

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has used compromised credentials and/or session tokens to gain access into a victim's VPN, VDI, RDP, and IAMs.(Citation: MSTIC DEV-0537 Mar 2022)(Citation: NCC Group LAPSUS Apr 2022)

  • T1078.004Valid Accounts: Cloud Accounts

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has used compromised credentials to access cloud assets within a target organization.(Citation: MSTIC DEV-0537 Mar 2022)

  • T1684.001Social Engineering: Impersonation

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has called victims' help desk and impersonated legitimate users with previously gathered information in order to gain access to privileged accounts.(Citation: MSTIC DEV-0537 Mar 2022)

TA0006

Credential Access

  • T1003.003OS Credential Dumping: NTDS

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has used Windows built-in tool `ntdsutil` to extract the Active Directory (AD) database.(Citation: MSTIC DEV-0537 Mar 2022)

  • T1003.006OS Credential Dumping: DCSync

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has used DCSync attacks to gather credentials for privilege escalation routines.(Citation: MSTIC DEV-0537 Mar 2022)

  • T1111Multi-Factor Authentication Interception

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has replayed stolen session token and passwords to trigger simple-approval MFA prompts in hope of the legitimate user will grant necessary approval.(Citation: MSTIC DEV-0537 Mar 2022)

  • T1552.008Unsecured Credentials: Chat Messages

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has targeted various collaboration tools like Slack, Teams, JIRA, Confluence, and others to hunt for exposed credentials to support privilege escalation and lateral movement.(Citation: MSTIC DEV-0537 Mar 2022)

  • T1555.003Credentials from Password Stores: Credentials from Web Browsers

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has obtained passwords and session tokens with the use of the Redline password stealer.(Citation: MSTIC DEV-0537 Mar 2022)

  • T1555.005Credentials from Password Stores: Password Managers

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has accessed local password managers and databases to obtain further credentials from a compromised network.(Citation: NCC Group LAPSUS Apr 2022)

  • T1621Multi-Factor Authentication Request Generation

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has spammed target users with MFA prompts in the hope that the legitimate user will grant necessary approval.(Citation: MSTIC DEV-0537 Mar 2022)

TA0007

Discovery

  • T1069.002Permission Groups Discovery: Domain Groups

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has used the AD Explorer tool to enumerate groups on a victim's network.(Citation: MSTIC DEV-0537 Mar 2022)

  • T1087.002Account Discovery: Domain Account

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has used the AD Explorer tool to enumerate users on a victim's network.(Citation: MSTIC DEV-0537 Mar 2022)(Citation: NCC Group LAPSUS Apr 2022)

TA0009

Collection

  • T1005Data from Local System

    [LAPSUS$](https://attack.mitre.org/groups/G1004) uploaded sensitive files, information, and credentials from a targeted organization for extortion or public release.(Citation: MSTIC DEV-0537 Mar 2022)

  • T1114.003Email Collection: Email Forwarding Rule

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has set an Office 365 tenant level mail transport rule to send all mail in and out of the targeted organization to the newly created account.(Citation: MSTIC DEV-0537 Mar 2022)

  • T1213.001Data from Information Repositories: Confluence

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has searched a victim's network for collaboration platforms like Confluence and JIRA to discover further high-privilege account credentials.(Citation: MSTIC DEV-0537 Mar 2022)

  • T1213.002Data from Information Repositories: Sharepoint

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has searched a victim's network for collaboration platforms like SharePoint to discover further high-privilege account credentials.(Citation: MSTIC DEV-0537 Mar 2022)(Citation: NCC Group LAPSUS Apr 2022)

  • T1213.003Data from Information Repositories: Code Repositories

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has searched a victim's network for code repositories like GitLab and GitHub to discover further high-privilege account credentials.(Citation: MSTIC DEV-0537 Mar 2022)(Citation: NCC Group LAPSUS Apr 2022)

  • T1213.005Data from Information Repositories: Messaging Applications

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has searched a victim's network for organization collaboration channels like MS Teams or Slack to discover further high-privilege account credentials.(Citation: MSTIC DEV-0537 Mar 2022)

TA0011

Command and Control

  • T1090Proxy

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has leverage NordVPN for its egress points when targeting intended victims.(Citation: MSTIC DEV-0537 Mar 2022)

TA0040

Impact

  • T1485Data Destruction

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has deleted the target's systems and resources both on-premises and in the cloud.(Citation: MSTIC DEV-0537 Mar 2022)(Citation: NCC Group LAPSUS Apr 2022)

  • T1489Service Stop

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has shut down virtual machines from within a victim's on-premise VMware ESXi infrastructure.(Citation: NCC Group LAPSUS Apr 2022)

  • T1531Account Access Removal

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has removed a targeted organization's global admin accounts to lock the organization out of all access.(Citation: MSTIC DEV-0537 Mar 2022)

TA0042

Resource Development

  • T1583.003Acquire Infrastructure: Virtual Private Server

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has used VPS hosting providers for infrastructure.(Citation: MSTIC DEV-0537 Mar 2022)

  • T1584.002Compromise Infrastructure: DNS Server

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has reconfigured a victim's DNS records to actor-controlled domains and websites.(Citation: NCC Group LAPSUS Apr 2022)

  • T1586.002Compromise Accounts: Email Accounts

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has payed employees, suppliers, and business partners of target organizations for credentials.(Citation: MSTIC DEV-0537 Mar 2022)(Citation: NCC Group LAPSUS Apr 2022)

  • T1588.001Obtain Capabilities: Malware

    [LAPSUS$](https://attack.mitre.org/groups/G1004) acquired and used the Redline password stealer in their operations.(Citation: MSTIC DEV-0537 Mar 2022)

  • T1588.002Obtain Capabilities: Tool

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has obtained tools such as RVTools and AD Explorer for their operations.(Citation: MSTIC DEV-0537 Mar 2022)(Citation: NCC Group LAPSUS Apr 2022)

TA0043

Reconnaissance

  • T1589Gather Victim Identity Information

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has gathered detailed information of target employees to enhance their social engineering lures.(Citation: MSTIC DEV-0537 Mar 2022)

  • T1589.001Gather Victim Identity Information: Credentials

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has gathered user identities and credentials to gain initial access to a victim's organization; the group has also called an organization's help desk to reset a target's credentials.(Citation: MSTIC DEV-0537 Mar 2022)(Citation: NCC Group LAPSUS Apr 2022)

  • T1589.002Gather Victim Identity Information: Email Addresses

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has gathered employee email addresses, including personal accounts, for social engineering and initial access efforts.(Citation: MSTIC DEV-0537 Mar 2022)

  • T1591.002Gather Victim Org Information: Business Relationships

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has gathered detailed knowledge of an organization's supply chain relationships.(Citation: MSTIC DEV-0537 Mar 2022)

  • T1591.004Gather Victim Org Information: Identify Roles

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has gathered detailed knowledge of team structures within a target organization.(Citation: MSTIC DEV-0537 Mar 2022)

  • T1593.003Search Open Websites/Domains: Code Repositories

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has searched public code repositories for exposed credentials.(Citation: MSTIC DEV-0537 Mar 2022)

  • T1597.002Search Closed Sources: Purchase Technical Data

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has purchased credentials and session tokens from criminal underground forums.(Citation: MSTIC DEV-0537 Mar 2022)

  • T1598.004Phishing for Information: Spearphishing Voice

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has called victims' help desk to convince the support personnel to reset a privileged account’s credentials.(Citation: MSTIC DEV-0537 Mar 2022)

TA0112

Defense Impairment

  • T1578.002Modify Cloud Compute Infrastructure: Create Cloud Instance

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has created new virtual machines within the target's cloud environment after leveraging credential access to cloud assets.(Citation: MSTIC DEV-0537 Mar 2022)

  • T1578.003Modify Cloud Compute Infrastructure: Delete Cloud Instance

    [LAPSUS$](https://attack.mitre.org/groups/G1004) has deleted the target's systems and resources in the cloud to trigger the organization's incident and crisis response process.(Citation: MSTIC DEV-0537 Mar 2022)

Recent victims

DateWebsite / victimSectorCountry
2026-06-23
ayabank.com
AYA BANKayabank.com
Financial ServicesMM
2026-06-13
ingka.com
INGKA GROUPingka.com
Retail & E-CommerceSE
2026-06-13
github.com
GITHUB INTERNALgithub.com
TechnologyUS
2026-03-31
M
MERCOR
Not Found
2026-04-26
M
MAPFRE ASSURANCE
Financial ServicesES
2026-05-28TechnologyDE
2026-05-10
axcera.io
AXCERA TRADINGAXCERA.IO
Professional ServicesUS
2026-04-24TechnologyUS
2026-03-22
axcera.io
AXCERA.IOAXCERA.IO
TechnologyUS
2026-03-25
astrazeneca.co.uk
ASTRAZENECA CORPastrazeneca.co.uk
HealthcareGB
2026-03-29
virtahealth.com
VirtaHealthvirtahealth.com
HealthcareUS
2026-03-01TransportationFR
2026-03-01
osac.aero
OSAC Aeroosac.aero
ManufacturingFR
2026-03-01
salesfloor.com
Salesfloorsalesfloor.com
TechnologyCA
2026-03-01Retail & E-CommerceDE
2026-03-01Retail & E-CommerceCH
2026-03-01Retail & E-CommerceFR
2026-03-01EducationUS
2026-03-01
univ-lille.fr
Lille Universityuniv-lille.fr
EducationFR
2026-03-01
agriculture.gouv.fr
FR Ministry of Agricultureagriculture.gouv.fr
Government & DefenseFR
2026-03-01
eni.com
Eni Energyeni.com
Energy & UtilitiesIT
2022-03-07
S
Samsung Electronics
TechnologyJP
2022-02-25
N
Nvidia
TechnologyUS
2022-01-01
I
Impresa
Professional ServicesPT
2021-12-10
B
Brazilian Ministry of Health
Government & DefenseBR