Cyber Resilience

Threat actor · all actors

LAPSUS$G1004 criminal

aka LAPSUS$, DEV-0537, Strawberry Tempest, LAPSUS$ (persona), Lapsus, WhiteDoxbin, SLIPPY SPIDER, UNC3661

Last updated: 2026-08-20

0attributed CVEs
63ATT&CK techniques
0.0IDF score (tooling uniqueness)
0exclusive CVEs
years active

About this actor

Lapsus$ is a cyber extortion group first observed in late 2021, known for high-profile breaches and data theft campaigns against major global companies rather than traditional ransomware encryption. The group primarily focuses on data exfiltration and public leak threats without encrypting victim systems. Lapsus$ uses a combination of social engineering, SIM swapping, MFA fatigue attacks, and purchasing access from insiders or access brokers to infiltrate corporate networks. Their victim list includes Microsoft, Okta, NVIDIA, Samsung, Uber, and telecom operators, with operations targeting multiple regions worldwide. Once inside, Lapsus$ actors exfiltrate source code, proprietary data, and customer information, often leaking samples to pressure victims into negotiation. The group is known for a brash and public-facing style, communicating directly with followers on Telegram channels and occasionally mocking victims. Several members, including minors, have been arrested in the UK, but the group’s activities have persisted in some form.

Source: MITRE ATT&CK

Names & naming systems

Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.

MITRE ATT&CKG-number catalogue id

G1004

Microsoftweather-system names

Strawberry Tempest

CrowdStrikenation-animal names

SLIPPY SPIDER

MandiantUNC uncategorised cluster

UNC3661

Unclassifiedno scheme matched

LAPSUS$DEV-0537LAPSUS$ (persona)LapsusWhiteDoxbin

How we know this

Data origin
MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
Techniques
Mixed — STIX + curated — 63 ATT&CK techniques on file.
Named victims
5 extracted from reporting.

See how actor data is built for the full pipeline.

Activity timeline

No activity events recorded.

Profile

CVERiskCVSSEPSSPublishedProducts
No attributed CVEs.

Mitigating controls (NIST 800-53)

ControlTechniques coveredCoverage
SI-433 / 6352%
AC-327 / 6343%
CM-627 / 6343%
AC-626 / 6341%
AC-224 / 6338%
IA-224 / 6338%
AC-420 / 6332%
CM-220 / 6332%
CM-519 / 6330%
CM-719 / 6330%
AC-518 / 6329%
CA-718 / 6329%
SI-716 / 6325%
IA-515 / 6324%
SC-714 / 6322%

Co-occurring actors

None.

Similar actors

Similar TTPs

Same category