LAPSUS$
Also reported as DEV-0537, Strawberry Tempest, SLIPPY SPIDER, LAPSUS, UNC3661 and 3 other names. Linked to Brazil by one source.
Reports per quarter
Techniques seen in the last two years
- T1003.003 3 reports in ATT&CK
- T1078.002 3 reports reports only
- T1486 3 reports reports only
- T1528 3 reports reports only
- T1566.004 3 reports reports only
- T1567.002 3 reports reports only
- T1003.002 2 reports reports only
- T1071.001 2 reports reports only
- T1078 2 reports in ATT&CK
- T1134 2 reports reports only
Show all 78 techniques Show fewer
- T1190 2 reports reports only
- T1219 2 reports reports only
- T1589.002 2 reports in ATT&CK
- T1593 2 reports reports only
- T1621 2 reports in ATT&CK
- T1003.001 1 report reports only
- T1012 1 report reports only
- T1016.001 1 report reports only
- T1018 1 report reports only
- T1021 1 report reports only
- T1021.001 1 report reports only
- T1036.005 1 report reports only
- T1039 1 report reports only
- T1041 1 report reports only
- T1046 1 report reports only
- T1048 1 report reports only
- T1059.004 1 report reports only
- T1068 1 report in ATT&CK
- T1069 1 report reports only
- T1069.002 1 report in ATT&CK
- T1070 1 report reports only
- T1072 1 report reports only
- T1074.002 1 report reports only
- T1087 1 report reports only
- T1087.002 1 report in ATT&CK
- T1090 1 report in ATT&CK
- T1090.003 1 report reports only
- T1098.005 1 report reports only
- T1102 1 report reports only
- T1110 1 report reports only
- T1110.004 1 report reports only
- T1111 1 report in ATT&CK
- T1112 1 report reports only
- T1114.003 1 report in ATT&CK
- T1119 1 report reports only
- T1133 1 report in ATT&CK
- T1136.001 1 report reports only
- T1136.003 1 report in ATT&CK
- T1195 1 report reports only
- T1204.001 1 report reports only
- T1210 1 report reports only
- T1213 1 report reports only
- T1213.002 1 report in ATT&CK
- T1213.003 1 report in ATT&CK
- T1482 1 report reports only
- T1485 1 report in ATT&CK
- T1518 1 report reports only
- T1526 1 report reports only
- T1529 1 report reports only
- T1534 1 report reports only
- T1539 1 report reports only
- T1546.012 1 report reports only
- T1552.005 1 report reports only
- T1555.003 1 report in ATT&CK
- T1555.005 1 report in ATT&CK
- T1555.006 1 report reports only
- T1565 1 report reports only
- T1566 1 report reports only
- T1566.002 1 report reports only
- T1567 1 report reports only
- T1569.002 1 report reports only
- T1570 1 report reports only
- T1573.002 1 report reports only
- T1578.005 1 report reports only
- T1583.003 1 report in ATT&CK
- T1583.006 1 report reports only
- T1650 1 report reports only
- T1657 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2015-2291 KEV ransomware
- CVE-2018-0802 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2019-0604 KEV ransomware
- CVE-2019-11510 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-5591 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-12812 KEV ransomware
- CVE-2020-23705
- CVE-2020-23852
- CVE-2020-8243 KEV
Show all 50 CVEs Show fewer
- CVE-2020-8260 KEV
- CVE-2021-20016 KEV ransomware
- CVE-2021-22893 KEV ransomware
- CVE-2021-22894 KEV
- CVE-2021-22899 KEV
- CVE-2021-22900 KEV
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-31207 KEV ransomware
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-35464 KEV ransomware
- CVE-2021-35587 KEV
- CVE-2021-40444 KEV ransomware
- CVE-2021-44228 KEV ransomware
- CVE-2021-44864
- CVE-2021-44956
- CVE-2021-44957
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2021-45325
- CVE-2021-45326
- CVE-2021-45327
- CVE-2021-45328
- CVE-2022-0139
- CVE-2022-0510
- CVE-2022-1388 KEV ransomware
- CVE-2022-21702
- CVE-2022-21919 KEV
- CVE-2022-22954 KEV ransomware
- CVE-2022-22960 KEV
- CVE-2022-22972
- CVE-2022-29464 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-41040 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2025-61882 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
Show all 93 reports Show fewer
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
PwC Cyber Threats 2022: A Year in Retrospect.pdf
The original link failed its last check. Original publisher Detailsfor PwC Cyber Threats 2022: A Year in Retrospect.pdf
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Slippy Spider
-
Popularity spikes for information stealer malware on the dark web
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Popularity spikes for information stealer malware on the dark web
-
Cookie stealing- the new perimeter bypass
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cookie stealing- the new perimeter bypass
-
Cisco Talos shares insights related to recent cyber attack on Cisco
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cisco Talos shares insights related to recent cyber attack on Cisco
-
Burrowing your way into VPNs, Proxies, and Tunnels
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Burrowing your way into VPNs, Proxies, and Tunnels
-
RedLine Stealer Campaign Using Binance Mystery Box Videos to Spread GitHub-Hosted Payload
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor RedLine Stealer Campaign Using Binance Mystery Box Videos to Spread GitHub-Hosted Payload
-
Redline Stealer Masquerades as Photo Editing Software
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Redline Stealer Masquerades as Photo Editing Software
-
Ransomware-as-a-service- Understanding the cybercrime gig economy and how to protect yourself
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ransomware-as-a-service- Understanding the cybercrime gig economy and how to protect yourself
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Gamer Cheater Hacker Spy
-
LAPSUS$- Recent techniques, tactics and procedures
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor LAPSUS$- Recent techniques, tactics and procedures
-
LAPSUS$: Recent techniques, tactics and procedures
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor LAPSUS$: Recent techniques, tactics and procedures
-
What is going on with Lapsus$-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor What is going on with Lapsus$-
-
Mars, a red-hot information stealer
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Mars, a red-hot information stealer
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Detailed Analysis of LAPSUS$ Cybercriminal Group that has Compromised Nvidia, Microsoft, Okta, and Globant
-
New documents for the Okta breach
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New documents for the Okta breach
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Brief- Lapsus$ Group
-
A Closer Look at the LAPSUS$ Data Extortion Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A Closer Look at the LAPSUS$ Data Extortion Group
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Trustwave’s Action Response- The Lapsus$ Hacker Group Shows Us the Importance of Securing the Digital Supply Chain
-
It’s official, Lapsus$ gang compromised a Microsoft employee’s account
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor It’s official, Lapsus$ gang compromised a Microsoft employee’s account
-
DEV-0537 (UNC3661) criminal actor targeting organizations for data exfiltration and destruction
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DEV-0537 (UNC3661) criminal actor targeting organizations for data exfiltration and destruction
-
Microsoft confirms they were hacked by Lapsus$ extortion group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft confirms they were hacked by Lapsus$ extortion group
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DEV-0537 (LAPSUS$-UNC3661) criminal actor targeting organizations for data exfiltration and destruction
-
Microsoft and Okta Confirm Breach by LAPSUS$ Extortion Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft and Okta Confirm Breach by LAPSUS$ Extortion Group
-
Meet Lapsus$- An Unusual Group in the Cyber Extortion Business
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Meet Lapsus$- An Unusual Group in the Cyber Extortion Business
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Lapsus$ Ransomware gang uses stolen source code to disguise malware files as trustworthy. Check Point customers remain protected
-
Malware now using NVIDIA's stolen code signing certificates
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malware now using NVIDIA's stolen code signing certificates
-
Mimecast links security breach to SolarWinds hackers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Mimecast links security breach to SolarWinds hackers
Newest first. Details opens the report in Explore.