LAPSUS$ is a cybercriminal group that became publicly prominent in December 2021 through data-theft and extortion operations. Also tracked as DEV-0537, Strawberry Tempest, and SLIPPY SPIDER, it initially attacked Latin American organizations before expanding to major international enterprises. Identified victims include Brazil’s Ministry of Health, Portugal’s Impresa media group, Microsoft, Okta’s support-provider ecosystem, Samsung, and NVIDIA. Its targeting encompasses technology companies, telecommunications providers, media organizations, government institutions, and outsourced support services. The group emphasizes identity compromise and social engineering. Its techniques include phishing, employee impersonation to obtain helpdesk password resets, SIM swapping, repeated multifactor-authentication requests intended to induce approval, and recruitment of employees willing to supply enterprise access. It uses stolen credentials to access internet-facing VPN, RDP, and virtual desktop services, including Citrix. LAPSUS$ has also used RedLine to steal passwords and session tokens. During the January 2022 Sitel/Sykes intrusion affecting Okta’s customer-support supply chain, LAPSUS$ used exposed credentials, exploited a local privilege-escalation vulnerability, created an additional account, moved laterally through RDP, obtained administrative group membership, disabled endpoint protection, and configured malicious email forwarding. Its operations have involved publicly available tools, including Process Hacker, Process Explorer, and Mimikatz. The NVIDIA breach exposed substantial proprietary data and code-signing certificates that other attackers subsequently abused. LAPSUS$ conducts encryption-less extortion by stealing sensitive information and threatening disclosure. It has published stolen data and extortion demands through Telegram, publicly mocked victims, involved followers in victim-selection polls, and disrupted incident-response calls. Members associated with LAPSUS$ have also been linked to the Scattered LAPSUS$ Hunters umbrella collective alongside participants associated with Scattered Spider and ShinyHunters; those groups are not interchangeable aliases.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
51 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 malware families attributed to this actor across reporting.
15 additional families tracked in Mallory.
28 CVEs this actor has used in observed campaigns. 28 of them exploited in the wild.
BleepingComputer reported that threat actors leveraged credentials stolen through the Trivy supply chain compromise (CVE-2026-33634) to breach Cisco's internal development environment... The CISA KEV remediation deadline for CVE-2026-33634 is today, April 8, 2026... Beyond patching Trivy to v0.69.2+, trivy-action to v0.35.0, or setup-trivy to v0.2.6, organizations must also complete credential rotation for any secrets that may have been exposed during the March 19-27 compromise window.
The CVE-2025-61882 campaign is particularly instructive. CrowdStrike assessed with moderate confidence that GRACEFUL SPIDER was involved in mass exploitation of that vulnerability... Exploitation had begun nearly two months earlier on August 9, 2025, well before Oracle's public disclosure.
CVEs targeted by Lapsus$ CVE-2021-31207: Microsoft Exchange Server Security Feature Bypass Vulnerability
CVEs targeted by Lapsus$ CVE-2021-34473: Microsoft Exchange Server Remote Code Execution Vulnerability
CVEs targeted by Lapsus$ CVE-2018-13379: An Improper Limitation of a Pathname to a Restricted Directory (“Path Traversal”) in Fortinet
23 more CVEs tied to this actor tracked in Mallory.
43 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a historical comparison for data-extortion threats against UK organizations, not as an attributed participant in the ASOS incident. The access techniques are discussed collectively rather than tied to a specific Lapsus$ operation.
Mentioned only as a constituent group of Scattered LAPSUS$ Hunters; no independent operations or techniques are described.
Named only as a constituent group of Scattered LAPSUS$ Hunters. The article does not separately attribute attacks, targets, malware, or techniques to LAPSUS$.
Named only as one of the groups whose members formed the Scattered Lapsus$ Hunters coalition. The article does not separately attribute attacks, tools, or techniques to LAPSUS$.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.