lapsus$
Group profile
Lapsus$ is an internationally composed data extortion group most active from mid-2021 through 2022, executing high-profile breaches against Microsoft, Nvidia, Samsung, Okta, and Uber by stealing source code and threatening leaks rather than encrypting files; several members — predominantly teenagers — were arrested in the UK.
MITRE ATT&CK TTPs
Initial Access
T1078Valid Accounts
[LAPSUS$](https://attack.mitre.org/groups/G1004) has used compromised credentials and/or session tokens to gain access into a victim's VPN, VDI, RDP, and IAMs.(Citation: MSTIC DEV-0537 Mar 2022)(Citation: NCC Group LAPSUS Apr 2022)
T1078.004Valid Accounts: Cloud Accounts
[LAPSUS$](https://attack.mitre.org/groups/G1004) has used compromised credentials to access cloud assets within a target organization.(Citation: MSTIC DEV-0537 Mar 2022)
T1133External Remote Services
[LAPSUS$](https://attack.mitre.org/groups/G1004) has gained access to internet-facing systems and applications, including virtual private network (VPN), remote desktop protocol (RDP), and virtual desktop infrastructure (VDI) including Citrix. (Citation: MSTIC DEV-0537 Mar 2022)(Citation: NCC Group LAPSUS Apr 2022)
T1199Trusted Relationship
[LAPSUS$](https://attack.mitre.org/groups/G1004) has accessed internet-facing identity providers such as Azure Active Directory and Okta to target specific organizations.(Citation: MSTIC DEV-0537 Mar 2022)
Execution
T1204User Execution
[LAPSUS$](https://attack.mitre.org/groups/G1004) has recruited target organization employees or contractors who provide credentials and approve an associated MFA prompt, or install remote management software onto a corporate workstation, allowing [LAPSUS$](https://attack.mitre.org/groups/G1004) to take control of an authenticated system.(Citation: MSTIC DEV-0537 Mar 2022)
Persistence
T1078Valid Accounts
[LAPSUS$](https://attack.mitre.org/groups/G1004) has used compromised credentials and/or session tokens to gain access into a victim's VPN, VDI, RDP, and IAMs.(Citation: MSTIC DEV-0537 Mar 2022)(Citation: NCC Group LAPSUS Apr 2022)
T1078.004Valid Accounts: Cloud Accounts
[LAPSUS$](https://attack.mitre.org/groups/G1004) has used compromised credentials to access cloud assets within a target organization.(Citation: MSTIC DEV-0537 Mar 2022)
T1098.003Account Manipulation: Additional Cloud Roles
[LAPSUS$](https://attack.mitre.org/groups/G1004) has added the global admin role to accounts they have created in the targeted organization's cloud instances.(Citation: MSTIC DEV-0537 Mar 2022)
T1133External Remote Services
[LAPSUS$](https://attack.mitre.org/groups/G1004) has gained access to internet-facing systems and applications, including virtual private network (VPN), remote desktop protocol (RDP), and virtual desktop infrastructure (VDI) including Citrix. (Citation: MSTIC DEV-0537 Mar 2022)(Citation: NCC Group LAPSUS Apr 2022)
T1136.003Create Account: Cloud Account
[LAPSUS$](https://attack.mitre.org/groups/G1004) has created global admin accounts in the targeted organization's cloud instances to gain persistence.(Citation: MSTIC DEV-0537 Mar 2022)
Privilege Escalation
T1068Exploitation for Privilege Escalation
[LAPSUS$](https://attack.mitre.org/groups/G1004) has exploited unpatched vulnerabilities on internally accessible servers including JIRA, GitLab, and Confluence for privilege escalation.(Citation: MSTIC DEV-0537 Mar 2022)
T1078Valid Accounts
[LAPSUS$](https://attack.mitre.org/groups/G1004) has used compromised credentials and/or session tokens to gain access into a victim's VPN, VDI, RDP, and IAMs.(Citation: MSTIC DEV-0537 Mar 2022)(Citation: NCC Group LAPSUS Apr 2022)
T1078.004Valid Accounts: Cloud Accounts
[LAPSUS$](https://attack.mitre.org/groups/G1004) has used compromised credentials to access cloud assets within a target organization.(Citation: MSTIC DEV-0537 Mar 2022)
T1098.003Account Manipulation: Additional Cloud Roles
[LAPSUS$](https://attack.mitre.org/groups/G1004) has added the global admin role to accounts they have created in the targeted organization's cloud instances.(Citation: MSTIC DEV-0537 Mar 2022)
Stealth
T1078Valid Accounts
[LAPSUS$](https://attack.mitre.org/groups/G1004) has used compromised credentials and/or session tokens to gain access into a victim's VPN, VDI, RDP, and IAMs.(Citation: MSTIC DEV-0537 Mar 2022)(Citation: NCC Group LAPSUS Apr 2022)
T1078.004Valid Accounts: Cloud Accounts
[LAPSUS$](https://attack.mitre.org/groups/G1004) has used compromised credentials to access cloud assets within a target organization.(Citation: MSTIC DEV-0537 Mar 2022)
T1684.001Social Engineering: Impersonation
[LAPSUS$](https://attack.mitre.org/groups/G1004) has called victims' help desk and impersonated legitimate users with previously gathered information in order to gain access to privileged accounts.(Citation: MSTIC DEV-0537 Mar 2022)
Credential Access
T1003.003OS Credential Dumping: NTDS
[LAPSUS$](https://attack.mitre.org/groups/G1004) has used Windows built-in tool `ntdsutil` to extract the Active Directory (AD) database.(Citation: MSTIC DEV-0537 Mar 2022)
T1003.006OS Credential Dumping: DCSync
[LAPSUS$](https://attack.mitre.org/groups/G1004) has used DCSync attacks to gather credentials for privilege escalation routines.(Citation: MSTIC DEV-0537 Mar 2022)
T1111Multi-Factor Authentication Interception
[LAPSUS$](https://attack.mitre.org/groups/G1004) has replayed stolen session token and passwords to trigger simple-approval MFA prompts in hope of the legitimate user will grant necessary approval.(Citation: MSTIC DEV-0537 Mar 2022)
T1552.008Unsecured Credentials: Chat Messages
[LAPSUS$](https://attack.mitre.org/groups/G1004) has targeted various collaboration tools like Slack, Teams, JIRA, Confluence, and others to hunt for exposed credentials to support privilege escalation and lateral movement.(Citation: MSTIC DEV-0537 Mar 2022)
T1555.003Credentials from Password Stores: Credentials from Web Browsers
[LAPSUS$](https://attack.mitre.org/groups/G1004) has obtained passwords and session tokens with the use of the Redline password stealer.(Citation: MSTIC DEV-0537 Mar 2022)
T1555.005Credentials from Password Stores: Password Managers
[LAPSUS$](https://attack.mitre.org/groups/G1004) has accessed local password managers and databases to obtain further credentials from a compromised network.(Citation: NCC Group LAPSUS Apr 2022)
T1621Multi-Factor Authentication Request Generation
[LAPSUS$](https://attack.mitre.org/groups/G1004) has spammed target users with MFA prompts in the hope that the legitimate user will grant necessary approval.(Citation: MSTIC DEV-0537 Mar 2022)
Discovery
T1069.002Permission Groups Discovery: Domain Groups
[LAPSUS$](https://attack.mitre.org/groups/G1004) has used the AD Explorer tool to enumerate groups on a victim's network.(Citation: MSTIC DEV-0537 Mar 2022)
T1087.002Account Discovery: Domain Account
[LAPSUS$](https://attack.mitre.org/groups/G1004) has used the AD Explorer tool to enumerate users on a victim's network.(Citation: MSTIC DEV-0537 Mar 2022)(Citation: NCC Group LAPSUS Apr 2022)
Collection
T1005Data from Local System
[LAPSUS$](https://attack.mitre.org/groups/G1004) uploaded sensitive files, information, and credentials from a targeted organization for extortion or public release.(Citation: MSTIC DEV-0537 Mar 2022)
T1114.003Email Collection: Email Forwarding Rule
[LAPSUS$](https://attack.mitre.org/groups/G1004) has set an Office 365 tenant level mail transport rule to send all mail in and out of the targeted organization to the newly created account.(Citation: MSTIC DEV-0537 Mar 2022)
T1213.001Data from Information Repositories: Confluence
[LAPSUS$](https://attack.mitre.org/groups/G1004) has searched a victim's network for collaboration platforms like Confluence and JIRA to discover further high-privilege account credentials.(Citation: MSTIC DEV-0537 Mar 2022)
T1213.002Data from Information Repositories: Sharepoint
[LAPSUS$](https://attack.mitre.org/groups/G1004) has searched a victim's network for collaboration platforms like SharePoint to discover further high-privilege account credentials.(Citation: MSTIC DEV-0537 Mar 2022)(Citation: NCC Group LAPSUS Apr 2022)
T1213.003Data from Information Repositories: Code Repositories
[LAPSUS$](https://attack.mitre.org/groups/G1004) has searched a victim's network for code repositories like GitLab and GitHub to discover further high-privilege account credentials.(Citation: MSTIC DEV-0537 Mar 2022)(Citation: NCC Group LAPSUS Apr 2022)
T1213.005Data from Information Repositories: Messaging Applications
[LAPSUS$](https://attack.mitre.org/groups/G1004) has searched a victim's network for organization collaboration channels like MS Teams or Slack to discover further high-privilege account credentials.(Citation: MSTIC DEV-0537 Mar 2022)
Command and Control
T1090Proxy
[LAPSUS$](https://attack.mitre.org/groups/G1004) has leverage NordVPN for its egress points when targeting intended victims.(Citation: MSTIC DEV-0537 Mar 2022)
Impact
T1485Data Destruction
[LAPSUS$](https://attack.mitre.org/groups/G1004) has deleted the target's systems and resources both on-premises and in the cloud.(Citation: MSTIC DEV-0537 Mar 2022)(Citation: NCC Group LAPSUS Apr 2022)
T1489Service Stop
[LAPSUS$](https://attack.mitre.org/groups/G1004) has shut down virtual machines from within a victim's on-premise VMware ESXi infrastructure.(Citation: NCC Group LAPSUS Apr 2022)
T1531Account Access Removal
[LAPSUS$](https://attack.mitre.org/groups/G1004) has removed a targeted organization's global admin accounts to lock the organization out of all access.(Citation: MSTIC DEV-0537 Mar 2022)
Resource Development
T1583.003Acquire Infrastructure: Virtual Private Server
[LAPSUS$](https://attack.mitre.org/groups/G1004) has used VPS hosting providers for infrastructure.(Citation: MSTIC DEV-0537 Mar 2022)
T1584.002Compromise Infrastructure: DNS Server
[LAPSUS$](https://attack.mitre.org/groups/G1004) has reconfigured a victim's DNS records to actor-controlled domains and websites.(Citation: NCC Group LAPSUS Apr 2022)
T1586.002Compromise Accounts: Email Accounts
[LAPSUS$](https://attack.mitre.org/groups/G1004) has payed employees, suppliers, and business partners of target organizations for credentials.(Citation: MSTIC DEV-0537 Mar 2022)(Citation: NCC Group LAPSUS Apr 2022)
T1588.001Obtain Capabilities: Malware
[LAPSUS$](https://attack.mitre.org/groups/G1004) acquired and used the Redline password stealer in their operations.(Citation: MSTIC DEV-0537 Mar 2022)
T1588.002Obtain Capabilities: Tool
[LAPSUS$](https://attack.mitre.org/groups/G1004) has obtained tools such as RVTools and AD Explorer for their operations.(Citation: MSTIC DEV-0537 Mar 2022)(Citation: NCC Group LAPSUS Apr 2022)
Reconnaissance
T1589Gather Victim Identity Information
[LAPSUS$](https://attack.mitre.org/groups/G1004) has gathered detailed information of target employees to enhance their social engineering lures.(Citation: MSTIC DEV-0537 Mar 2022)
T1589.001Gather Victim Identity Information: Credentials
[LAPSUS$](https://attack.mitre.org/groups/G1004) has gathered user identities and credentials to gain initial access to a victim's organization; the group has also called an organization's help desk to reset a target's credentials.(Citation: MSTIC DEV-0537 Mar 2022)(Citation: NCC Group LAPSUS Apr 2022)
T1589.002Gather Victim Identity Information: Email Addresses
[LAPSUS$](https://attack.mitre.org/groups/G1004) has gathered employee email addresses, including personal accounts, for social engineering and initial access efforts.(Citation: MSTIC DEV-0537 Mar 2022)
T1591.002Gather Victim Org Information: Business Relationships
[LAPSUS$](https://attack.mitre.org/groups/G1004) has gathered detailed knowledge of an organization's supply chain relationships.(Citation: MSTIC DEV-0537 Mar 2022)
T1591.004Gather Victim Org Information: Identify Roles
[LAPSUS$](https://attack.mitre.org/groups/G1004) has gathered detailed knowledge of team structures within a target organization.(Citation: MSTIC DEV-0537 Mar 2022)
T1593.003Search Open Websites/Domains: Code Repositories
[LAPSUS$](https://attack.mitre.org/groups/G1004) has searched public code repositories for exposed credentials.(Citation: MSTIC DEV-0537 Mar 2022)
T1597.002Search Closed Sources: Purchase Technical Data
[LAPSUS$](https://attack.mitre.org/groups/G1004) has purchased credentials and session tokens from criminal underground forums.(Citation: MSTIC DEV-0537 Mar 2022)
T1598.004Phishing for Information: Spearphishing Voice
[LAPSUS$](https://attack.mitre.org/groups/G1004) has called victims' help desk to convince the support personnel to reset a privileged account’s credentials.(Citation: MSTIC DEV-0537 Mar 2022)
Defense Impairment
T1578.002Modify Cloud Compute Infrastructure: Create Cloud Instance
[LAPSUS$](https://attack.mitre.org/groups/G1004) has created new virtual machines within the target's cloud environment after leveraging credential access to cloud assets.(Citation: MSTIC DEV-0537 Mar 2022)
T1578.003Modify Cloud Compute Infrastructure: Delete Cloud Instance
[LAPSUS$](https://attack.mitre.org/groups/G1004) has deleted the target's systems and resources in the cloud to trigger the organization's incident and crisis response process.(Citation: MSTIC DEV-0537 Mar 2022)
Recent victims
| Date | Website / victim | Sector | Country |
|---|---|---|---|
| 2026-06-23 | AYA BANKayabank.com | Financial Services | MM |
| 2026-06-13 | INGKA GROUPingka.com | Retail & E-Commerce | SE |
| 2026-06-13 | GITHUB INTERNALgithub.com | Technology | US |
| 2026-03-31 | M MERCOR | Not Found | |
| 2026-04-26 | M MAPFRE ASSURANCE | Financial Services | ES |
| 2026-05-28 | VODAFONEvodafone.com | Technology | DE |
| 2026-05-10 | AXCERA TRADINGAXCERA.IO | Professional Services | US |
| 2026-04-24 | CHECKMARXcheckmarx.com | Technology | US |
| 2026-03-22 | AXCERA.IOAXCERA.IO | Technology | US |
| 2026-03-25 | ASTRAZENECA CORPastrazeneca.co.uk | Healthcare | GB |
| 2026-03-29 | VirtaHealthvirtahealth.com | Healthcare | US |
| 2026-03-01 | Eiffageeiffage.com | Transportation | FR |
| 2026-03-01 | OSAC Aeroosac.aero | Manufacturing | FR |
| 2026-03-01 | Salesfloorsalesfloor.com | Technology | CA |
| 2026-03-01 | Adidasadidas.de | Retail & E-Commerce | DE |
| 2026-03-01 | Loozaploozap.com | Retail & E-Commerce | CH |
| 2026-03-01 | Lacostelacoste.com | Retail & E-Commerce | FR |
| 2026-03-01 | DreamUpdreamup.org | Education | US |
| 2026-03-01 | Lille Universityuniv-lille.fr | Education | FR |
| 2026-03-01 | FR Ministry of Agricultureagriculture.gouv.fr | Government & Defense | FR |
| 2026-03-01 | Eni Energyeni.com | Energy & Utilities | IT |
| 2022-03-07 | S Samsung Electronics | Technology | JP |
| 2022-02-25 | N Nvidia | Technology | US |
| 2022-01-01 | I Impresa | Professional Services | PT |
| 2021-12-10 | B Brazilian Ministry of Health | Government & Defense | BR |

