APT English/Portuguese-Speaking Extortion Group Active since 2021

LAPSUS$

Extortion without ransomware. Compromised Microsoft, Nvidia, Samsung, Okta, Uber.

Scroll

LAPSUS$ is a data extortion group that gained notoriety in early 2022 for breaching some of the world's largest technology companies without deploying ransomware. The group relied on social engineering, insider recruitment, and MFA fatigue to gain access, then exfiltrated source code and internal data for extortion. Several members were arrested in the UK in 2022.

AttributeDetail
NamesLAPSUS$ / DEV-0537
AttributionEnglish/Portuguese-Speaking Extortion Group
Active Since2021
Primary FocusExtortion without ransomware. Compromised Microsoft, Nvidia, Samsung, Okta, Uber.

Overview

LAPSUS$ is a data extortion group that gained notoriety in early 2022 for breaching some of the world's largest technology companies without deploying ransomware. The group relied on social engineering, insider recruitment, and MFA fatigue to gain access, then exfiltrated source code and internal data for extortion. Several members were arrested in the UK in 2022.

Attribution

LAPSUS$ / DEV-0537 is attributed to English/Portuguese-Speaking Extortion Group, active since at least 2021. Extortion without ransomware. Compromised Microsoft, Nvidia, Samsung, Okta, Uber.

Notable Campaigns

MITRE ATT&CK Mapping

Technique IDTechniqueConfidence
T1566PhishingHigh
T1078Valid AccountsHigh
T1530Data from Cloud Storage ObjectHigh
T1567Exfiltration Over Web ServiceHigh
T1621MFA Request GenerationHigh
T1656ImpersonationHigh

Detection & Defense

Recommended Defenses

Monitor for the TTPs listed above using your SIEM and EDR platforms. Prioritize patching of internet-facing applications and enforce MFA on all remote access. Mjolnir Security provides continuous threat hunting and monitoring for LAPSUS$ activity patterns.

Mjolnir Security — Threat Intelligence & Response

Mjolnir Security provides 24/7 threat monitoring, incident response, and threat intelligence services. Contact us for threat hunting specifically targeting LAPSUS$ TTPs in your environment.

Threat Hunting Incident Response Threat Intelligence SOC-as-a-Service

mjolnirsecurity.com — 24/7 Incident Response Hotline: +1 833 403 5875