Home · Wiki · Entities & Threat Actors
created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [ransomware-group, supply-chain] · confidence: medium · affected_sectors: [] · au_impact: false

LAPSUS$

LAPSUS$ is cyber criminal threat group that has been active since at least mid-2021. LAPSUS$ specializes in large-scale social engineering and extortion operations, including destructive attacks without the use of ransomware.

Attribute Detail
ATT&CK ID G1004
Aliases DEV-0537, Strawberry Tempest
Attribution Not stated by MITRE ATT&CK
Class ecrime
Active since
ATT&CK entry created 2022-06-09
Techniques mapped 44

Attribution — as claimed

Not state-attributed; the activity is self-declared (public extortion/leak-site claims) or attributed to criminal reporting.

Known TTPs

Technique Name
T1003.003 NTDS
T1003.006 DCSync
T1005 Data from Local System
T1068 Exploitation for Privilege Escalation
T1069.002 Domain Groups
T1078 Valid Accounts
T1078.004 Cloud Accounts
T1087.002 Domain Account
T1090 Proxy
T1098.003 Additional Cloud Roles
T1111 Multi-Factor Authentication Interception
T1114.003 Email Forwarding Rule

(First 12 of 44 ATT&CK-mapped techniques.)

Related Pages

  • Mitre Attack — the framework this page's data is drawn from
  • Silence — similarly attributed-linked actor, same attribution class
  • Scattered Spider — similarly attributed-linked actor, same attribution class
  • Akira — similarly attributed-linked actor, same attribution class

Provenance

Stub generated from MITRE ATT&CK G1004 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.