LAPSUS
An actor group conducting large-scale social engineering and extortion campaign against multiple organizations with some seeing evidence of destructive elements.
LAPSUS is a threat actor known for large-scale social engineering and extortion campaigns targeting multiple sectors.
LAPSUS (LAPSUS$) is a threat actor conducting large-scale social engineering and extortion campaigns across multiple countries. This group primarily targets the financial services, retail & e-commerce, and technology sectors. Key TTPs include using trusted relationships for initial access (T1199), stealing credentials via Mimikatz (T1552.008), and employing valid accounts to evade defenses (T1078). Defenders should focus on enforcing multi-factor authentication, monitoring privileged accounts, and raising staff awareness against social engineering attacks.
An actor group conducting large-scale social engineering and extortion campaign against multiple organizations with some seeing evidence of destructive elements.
Monitor network traffic and open sources to gather victim identity information and identify roles.
Monitor suspicious network activity to detect procurement or development of tools.
Monitor access patterns and user behavior to detect abuse of trusted relationships.
Monitor endpoint activity to detect suspicious files or commands executed by users.
Monitor ingress points and user activity to detect use of external remote services.
Monitor system and application vulnerabilities to detect exploitation for privilege escalation.
Monitor user activity and access patterns to detect abuse of valid accounts.
Monitor user communication to detect suspicious chat messages.
Monitor Active Directory changes and user activity to detect domain groups and accounts.
Monitor user activity and data access to detect collection of data from local systems and Confluence.
Monitor network traffic and connection patterns to detect abuse of proxy.
Monitor cloud activity and changes to detect deletion of cloud instance.
Monitor data changes and user activity to detect data destruction.
LAPSUS primarily uses trusted relationships for initial access (T1199).
LAPSUS primarily targets the financial services, retail & e-commerce, and technology sectors.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.