Threat actor · all actors
LAPSUS$G1004 criminal
aka LAPSUS$, DEV-0537, Strawberry Tempest, LAPSUS$ (persona), Lapsus, WhiteDoxbin, SLIPPY SPIDER, UNC3661
Last updated: 2026-08-20
About this actor
Lapsus$ is a cyber extortion group first observed in late 2021, known for high-profile breaches and data theft campaigns against major global companies rather than traditional ransomware encryption. The group primarily focuses on data exfiltration and public leak threats without encrypting victim systems. Lapsus$ uses a combination of social engineering, SIM swapping, MFA fatigue attacks, and purchasing access from insiders or access brokers to infiltrate corporate networks. Their victim list includes Microsoft, Okta, NVIDIA, Samsung, Uber, and telecom operators, with operations targeting multiple regions worldwide. Once inside, Lapsus$ actors exfiltrate source code, proprietary data, and customer information, often leaking samples to pressure victims into negotiation. The group is known for a brash and public-facing style, communicating directly with followers on Telegram channels and occasionally mocking victims. Several members, including minors, have been arrested in the UK, but the group’s activities have persisted in some form.
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Microsoftweather-system names
CrowdStrikenation-animal names
MandiantUNC uncategorised cluster
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- Mixed — STIX + curated — 63 ATT&CK techniques on file.
- Named victims
- 5 extracted from reporting.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
T1003OS Credential Dumping ↗T1003.003NTDS ↗T1003.006DCSync ↗T1005Data from Local System ↗T1068Exploitation for Privilege Escalation ↗T1069Permission Groups Discovery ↗T1069.002Domain Groups ↗T1078Valid Accounts ↗T1078.004Cloud Accounts ↗T1087Account Discovery ↗T1087.002Domain Account ↗T1090Proxy ↗T1098Account Manipulation ↗T1098.003Additional Cloud Roles ↗T1111Multi-Factor Authentication Interception ↗T1114Email Collection ↗T1114.003Email Forwarding Rule ↗T1133External Remote Services ↗T1136Create Account ↗T1136.003Cloud Account ↗T1199Trusted Relationship ↗T1204User Execution ↗T1213Data from Information Repositories ↗T1213.001Confluence ↗T1213.002Sharepoint ↗T1213.003Code Repositories ↗T1213.005Messaging Applications ↗T1485Data Destruction ↗T1489Service Stop ↗T1531Account Access Removal ↗T1552Unsecured Credentials ↗T1552.008Chat Messages ↗T1555Credentials from Password Stores ↗T1555.003Credentials from Web Browsers ↗T1555.005Password Managers ↗T1566.004Spearphishing Voice ↗T1578Modify Cloud Compute Infrastructure ↗T1578.002Create Cloud Instance ↗T1578.003Delete Cloud Instance ↗T1583Acquire Infrastructure ↗T1583.003Virtual Private Server ↗T1584Compromise Infrastructure ↗T1584.002DNS Server ↗T1586Compromise Accounts ↗T1586.002Email Accounts ↗T1588Obtain Capabilities ↗T1588.001Malware ↗T1588.002Tool ↗T1589Gather Victim Identity Information ↗T1589.001Credentials ↗T1589.002Email Addresses ↗T1591Gather Victim Org Information ↗T1591.002Business Relationships ↗T1591.004Identify Roles ↗T1593Search Open Websites/Domains ↗T1593.003Code Repositories ↗T1597Search Closed Sources ↗T1597.002Purchase Technical Data ↗T1598Phishing for Information ↗T1598.004Spearphishing Voice ↗T1621Multi-Factor Authentication Request Generation ↗T1684Social Engineering ↗T1684.001Impersonation ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 33 / 63 | 52% |
AC-3 | 27 / 63 | 43% |
CM-6 | 27 / 63 | 43% |
AC-6 | 26 / 63 | 41% |
AC-2 | 24 / 63 | 38% |
IA-2 | 24 / 63 | 38% |
AC-4 | 20 / 63 | 32% |
CM-2 | 20 / 63 | 32% |
CM-5 | 19 / 63 | 30% |
CM-7 | 19 / 63 | 30% |
AC-5 | 18 / 63 | 29% |
CA-7 | 18 / 63 | 29% |
SI-7 | 16 / 63 | 25% |
IA-5 | 15 / 63 | 24% |
SC-7 | 14 / 63 | 22% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- Scattered Spider 0.32
- C0027 0.30
- HAFNIUM 0.18
- VOID MANTICORE 0.18
- Sandworm Team 0.18
Same category
- Akira 1.00
- INC Ransom 1.00
- Play 1.00
- BlackByte 1.00
- ShinyHunters 1.00