LAPSUS$ is an extortion-focused cybercriminal threat actor, also tracked as DEV-0537 and Strawberry Tempest, that became prominent in 2021 through high-visibility intrusions, theft of sensitive data and source code, and public leaking of stolen material. The group is widely distinguished from conventional ransomware operations because it has typically relied on pure data theft, public shaming, and destructive actions rather than deploying file-encrypting ransomware payloads. Public reporting has repeatedly characterized notoriety and status-seeking as central features of its behavior, although financial gain has also been present. The actor has targeted organizations globally, with early activity concentrated in South America and the United Kingdom before expanding to major enterprises in North America, Europe, and Asia. Confirmed victim sectors include government, information technology, telecommunications, media, retail, health care, manufacturing, energy, higher education, and cryptocurrency services. Publicly associated victims include Brazil’s Ministry of Health, Claro, Embratel, Correios, Impresa, Mercado Libre, Nvidia, Samsung, Ubisoft, Vodafone, Okta, Electronic Arts, Uber, T-Mobile, Globant, LG, and Microsoft. LAPSUS$ is notable for identity-centric intrusion tradecraft. Initial access has commonly involved stolen credentials, purchased credentials, browser-stored passwords, session tokens, and stolen session cookies. The group has used the RedLine password stealer to obtain passwords and session tokens, and has also bought access material from criminal marketplaces. It has abused session replay to bypass MFA, conducted MFA fatigue attacks, performed SIM swapping, and socially engineered help-desk personnel into resetting privileged accounts. The actor has also solicited insiders, employees, suppliers, and contractors to provide credentials, MFA approval, or direct access, sometimes using public social channels to recruit them. After gaining access, LAPSUS$ has conducted reconnaissance across identity systems, collaboration platforms, code repositories, and enterprise documentation stores to locate secrets, credentials, privileged access paths, and valuable intellectual property. Reported post-compromise activity includes use of AD Explorer for enumeration, DCSync and Mimikatz for privilege escalation and credential access, extraction of Active Directory data, abuse of cloud administrative roles, creation of new virtual machines, mail-forwarding rule manipulation, and removal of other administrators to lock out defenders. The group has also exploited unpatched internally accessible enterprise platforms such as JIRA, GitLab, and Confluence. The actor’s operations have included large-scale data exfiltration, publication of stolen source code, extortion through threatened leaks, and destructive actions against on-premises and cloud resources. In some incidents, LAPSUS$ deleted systems or virtual infrastructure after exfiltration. The group has also intruded into victims’ incident-response communications to monitor remediation and increase pressure on targets. Its public-facing behavior, especially through Telegram, has been unusually overt compared with many intrusion sets. Aliases include DEV-0537, Strawberry Tempest, Slippy Spider, and variants of the LAPSUS$ name.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
55 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 malware families attributed to this actor across reporting.
15 additional families tracked in Mallory.
28 CVEs this actor has used in observed campaigns. 28 of them exploited in the wild.
BleepingComputer reported that threat actors leveraged credentials stolen through the Trivy supply chain compromise (CVE-2026-33634) to breach Cisco's internal development environment... The CISA KEV remediation deadline for CVE-2026-33634 is today, April 8, 2026... Beyond patching Trivy to v0.69.2+, trivy-action to v0.35.0, or setup-trivy to v0.2.6, organizations must also complete credential rotation for any secrets that may have been exposed during the March 19-27 compromise window.
The CVE-2025-61882 campaign is particularly instructive. CrowdStrike assessed with moderate confidence that GRACEFUL SPIDER was involved in mass exploitation of that vulnerability... Exploitation had begun nearly two months earlier on August 9, 2025, well before Oracle's public disclosure.
CVEs targeted by Lapsus$ CVE-2021-31207: Microsoft Exchange Server Security Feature Bypass Vulnerability
CVEs targeted by Lapsus$ CVE-2021-34473: Microsoft Exchange Server Remote Code Execution Vulnerability
CVEs targeted by Lapsus$ CVE-2018-13379: An Improper Limitation of a Pathname to a Restricted Directory (“Path Traversal”) in Fortinet
23 more CVEs tied to this actor tracked in Mallory.
39 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed permanent cessation of activities on a website asserting it represented the group, framed as having achieved its financial goals.
Named as a reported criminal link in connection with publication of European Commission data associated with TeamPCP activity.
Announces a permanent shutdown of operations, claims it achieved its financial goals, says it will cease communications, data leaks, and access sales, and alleges it sold Mercor user data to Chinese entities. The group is also described as having formed the SLH alliance, returned with an Extortion-as-a-Service model, and recruited women for vishing campaigns.
Listed as a threat actor associated with the generic installation exploitation analytic, but no campaign-specific activity is described in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.