LAPSUS$ — Hacktivist Profile
LAPSUS$ is cyber criminal threat group that has been active since at least mid-2021. LAPSUS$ specializes in large-scale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
DEV-0537, Strawberry Tempest, SLIPPY SPIDER, UNC3661
IntelFusions coverage (4)
- Cloud extortion crew steals secrets via service accounts 2026-08-06 · Cyber Incidents
- Rogue ransomware negotiator helped BlackCat extort his own clients 2026-07-14 · Ransomware
- Ransomware crew Vect teams up with supply chain hackers TeamPCP 2026-07-03 · Ransomware
- DEV-0537 (LAPSUS$): Social Engineering, SIM Swapping, and Insider Recruitment Power a Pure Extortion and Destruction Campaign 2026-02-16 · Cyber Incidents
Tools & malware
- Mimikatz Credential Harvesting
Recent claimed victims
- AYA BANK 2026-06-23
- INGKA GROUP 2026-06-13
- GITHUB INTERNAL 2026-06-13
- MERCOR 2026-05-31
- MAPFRE ASSURANCE 2026-05-31
- VODAFONE 2026-05-29
- AXCERA TRADING 2026-05-10
- CHECKMARX 2026-04-25
- AXCERA.IO 2026-04-05
- VirtaHealth 2026-04-05
- ASTRAZENECA CORP 2026-04-05
- Lacoste 2026-03-01
- FR Ministry of Agriculture 2026-03-01
- Lille University 2026-03-01
- Loozap 2026-03-01
- Eni Energy 2026-03-01
- Adidas 2026-03-01
- Salesfloor 2026-03-01
- Eiffage 2026-03-01
- DreamUp 2026-03-01
- OSAC Aero 2026-03-01
Vendor research
- DEV-0537 Microsoft
- How Microsoft names threat actors Microsoft
- LAPSUS: Two UK Teenagers Charged with Hacking for Gang BBC
- DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction MSTIC
- Threat Brief: Lapsus$ Group Unit 42
Countries linked to this actor
- United Kingdom origin
- Portugal targets
- Brazil origin