Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: DEV-0537, Strawberry Tempest
43
techniques
1
software
9,866
corpus matches
profile
LAPSUS$ is cyber criminal threat group that has been active since at least mid-2021. LAPSUS$ specializes in large-scale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.
techniques
43 attributed · most-instrumented first
software
1 malware & tools attributed
Mimikatz
S0002
read this carefully
9,866 corpus matches is not attribution
That count is indicators which exhibit techniques LAPSUS$ is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
+31 more techniques
showing 30 of 9,866
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.