created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [ransomware-group, supply-chain] · confidence: medium · affected_sectors: [] · au_impact: false
LAPSUS$
LAPSUS$ is cyber criminal threat group that has been active since at least mid-2021. LAPSUS$ specializes in large-scale social engineering and extortion operations, including destructive attacks without the use of ransomware.
| Attribute | Detail |
|---|---|
| ATT&CK ID | G1004 |
| Aliases | DEV-0537, Strawberry Tempest |
| Attribution | Not stated by MITRE ATT&CK |
| Class | ecrime |
| Active since | — |
| ATT&CK entry created | 2022-06-09 |
| Techniques mapped | 44 |
Attribution — as claimed
Not state-attributed; the activity is self-declared (public extortion/leak-site claims) or attributed to criminal reporting.
Known TTPs
| Technique | Name |
|---|---|
T1003.003 |
NTDS |
T1003.006 |
DCSync |
T1005 |
Data from Local System |
T1068 |
Exploitation for Privilege Escalation |
T1069.002 |
Domain Groups |
T1078 |
Valid Accounts |
T1078.004 |
Cloud Accounts |
T1087.002 |
Domain Account |
T1090 |
Proxy |
T1098.003 |
Additional Cloud Roles |
T1111 |
Multi-Factor Authentication Interception |
T1114.003 |
Email Forwarding Rule |
(First 12 of 44 ATT&CK-mapped techniques.)
Related Pages
- Mitre Attack — the framework this page's data is drawn from
- Silence — similarly attributed-linked actor, same attribution class
- Scattered Spider — similarly attributed-linked actor, same attribution class
- Akira — similarly attributed-linked actor, same attribution class
Provenance
Stub generated from MITRE ATT&CK G1004 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.