LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G1004: LAPSUS$

LAPSUS$ is cyber criminal threat group that has been active since at least mid-2021. LAPSUS$ specializes in large-scale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.[1][2][3]

EnterpriseG1004GroupObject v2.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

LAPSUS$ matters because ATT&CK describes it as a cyber criminal group focused on large-scale social engineering and extortion, including destructive attacks without ransomware. For leaders, the key lesson is that resilience cannot depend only on malware or ransomware detection: identity abuse, cloud account control, SaaS data exposure, help-desk/social-engineering readiness, and destructive recovery plans are central to risk reduction.

Executive priority

Prioritize questions that expose whether the organization can withstand identity-led extortion and disruption: Are privileged domain and cloud accounts tightly governed? Can the SOC see suspicious account, MFA, email forwarding, SaaS repository, and remote-access activity? Are third-party trusted relationships reviewed and monitored? Are destructive scenarios covered by backup, recovery, legal, communications, and incident-response playbooks? This object is especially relevant to business continuity, audit evidence for access controls, and executive incident decision-making because the described behavior spans credential access, cloud persistence, data collection, and impact.

Technical view

ATT&CK does not provide a detection section for this group, so defenders should validate coverage through the related techniques. Focus on identity and access paths: Valid Accounts, Cloud Accounts, External Remote Services, MFA interception, cloud role additions, cloud account creation, domain account and group discovery, NTDS/DCSync credential access, and Mimikatz use. Also validate SaaS and collaboration collection visibility for SharePoint, Confluence, code repositories, messaging applications, local system data, and email forwarding rules. Impact readiness should include monitoring and response for data destruction and service stop activity. Because the group platforms are not specified, use the platforms from the related techniques to scope control validation across Windows, identity providers, SaaS/Office Suite, IaaS, Linux/macOS, ESXi, containers, network devices, and mobile where those services exist locally.

Likely telemetry

  • Identity provider sign-in, MFA, conditional access, role assignment, and account creation logs
  • Cloud control-plane audit logs for IAM changes, privileged role grants, and new accounts
  • VPN, remote access, and external service authentication logs
  • Windows domain controller security logs, directory replication indicators, and privileged group activity
  • Endpoint process, credential access, and administrative tool execution telemetry, especially on Windows systems where applicable

Detection direction

  • Do not rely on malware signatures alone; tune for identity, SaaS, cloud administration, and destructive behavior patterns reflected in the related ATT&CK techniques.
  • Correlate unusual successful logins, MFA challenges, remote access sessions, privileged role changes, and new cloud accounts with subsequent repository, mailbox, or collaboration-data access.
  • Review privileged Active Directory activity for domain group discovery, domain account enumeration, NTDS access, DCSync-like replication behavior, and credential dumping indicators such as Mimikatz where relevant.
  • Baseline normal SaaS repository and messaging access so high-volume or unusual access to SharePoint, Confluence, code repositories, and messaging applications can be investigated with fewer false positives.
  • Monitor email forwarding rule creation and mailbox configuration changes, especially after suspicious account activity or credential reset events.

Mitigation priorities

  • Strengthen identity governance first: least privilege, privileged access review, monitored administrative roles, and rapid disablement paths for compromised accounts.
  • Harden MFA and account recovery processes, including help-desk verification and SIM-swap-aware procedures where mobile numbers are used for authentication or recovery.
  • Reduce blast radius in cloud and SaaS by limiting who can create accounts, add roles, set forwarding rules, and access sensitive repositories.
  • Review and monitor external remote services and trusted third-party access with the same rigor as internal privileged access.
  • Protect domain controllers and credential stores through tight administrative separation, monitoring for replication abuse, and restricted access to NTDS-related data.
Additional notes and limits

The most defensible Glexia takeaway is identity-centric resilience. The official description emphasizes social engineering, extortion, global targeting across multiple sectors, and destructive attacks without ransomware. The relationship set expands the defensive focus into credential access, valid accounts, cloud/SaaS persistence, data collection, remote services, trusted relationships, and impact techniques. Use the aliases LAPSUS$, DEV-0537, and Strawberry Tempest when normalizing threat intelligence and detection content.

ATT&CK provides no official detection text and no group-level platforms or tactics for this object. Platform and tactic guidance here is derived only from the supplied related techniques and software, so each organization must validate relevance against its own identity providers, SaaS estate, cloud services, endpoints, remote-access architecture, and logging coverage. This summary does not assert current activity, specific victim exposure, or guaranteed detection coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

LAPSUS$

LAPSUS$ is cyber criminal threat group that has been active since at least mid-2021. LAPSUS$ specializes in large-scale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.[1][2][3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

43 rows
DomainIDNameRelationship / procedure
EnterpriseT1589Gather Victim Identity Information

LAPSUS$ has gathered detailed information of target employees to enhance their social engineering lures.[2]

EnterpriseT1005Data from Local System

LAPSUS$ uploaded sensitive files, information, and credentials from a targeted organization for extortion or public release.[2]

EnterpriseT1069.002Domain GroupsSub-technique

LAPSUS$ has used the AD Explorer tool to enumerate groups on a victim's network.[2]

EnterpriseT1213.001ConfluenceSub-technique

LAPSUS$ has searched a victim's network for collaboration platforms like Confluence and JIRA to discover further high-privilege account credentials.[2]

EnterpriseT1588.002ToolSub-technique

LAPSUS$ has obtained tools such as RVTools and AD Explorer for their operations.[2][4]

EnterpriseT1485Data Destruction

LAPSUS$ has deleted the target's systems and resources both on-premises and in the cloud.[2][4]

EnterpriseT1213.003Code RepositoriesSub-technique

LAPSUS$ has searched a victim's network for code repositories like GitLab and GitHub to discover further high-privilege account credentials.[2][4]

EnterpriseT1213.002SharepointSub-technique

LAPSUS$ has searched a victim's network for collaboration platforms like SharePoint to discover further high-privilege account credentials.[2][4]

EnterpriseT1583.003Virtual Private ServerSub-technique

LAPSUS$ has used VPS hosting providers for infrastructure.[2]

EnterpriseT1591.004Identify RolesSub-technique

LAPSUS$ has gathered detailed knowledge of team structures within a target organization.[2]

EnterpriseT1090Proxy

LAPSUS$ has leverage NordVPN for its egress points when targeting intended victims.[2]

EnterpriseT1087.002Domain AccountSub-technique

LAPSUS$ has used the AD Explorer tool to enumerate users on a victim's network.[2][4]

EnterpriseT1133External Remote Services

LAPSUS$ has gained access to internet-facing systems and applications, including virtual private network (VPN), remote desktop protocol (RDP), and virtual desktop infrastructure (VDI) including Citrix. [2][4]

EnterpriseT1078Valid Accounts

LAPSUS$ has used compromised credentials and/or session tokens to gain access into a victim's VPN, VDI, RDP, and IAMs.[2][4]

EnterpriseT1588.001MalwareSub-technique

LAPSUS$ acquired and used the Redline password stealer in their operations.[2]

EnterpriseT1598.004Spearphishing VoiceSub-technique

LAPSUS$ has called victims' help desk to convince the support personnel to reset a privileged account’s credentials.[2]

EnterpriseT1204User Execution

LAPSUS$ has recruited target organization employees or contractors who provide credentials and approve an associated MFA prompt, or install remote management software onto a corporate workstation, allowing LAPSUS$ to take control of an authenticated system.[2]

EnterpriseT1552.008Chat MessagesSub-technique

LAPSUS$ has targeted various collaboration tools like Slack, Teams, JIRA, Confluence, and others to hunt for exposed credentials to support privilege escalation and lateral movement.[2]

EnterpriseT1489Service Stop

LAPSUS$ has shut down virtual machines from within a victim's on-premise VMware ESXi infrastructure.[4]

EnterpriseT1593.003Code RepositoriesSub-technique

LAPSUS$ has searched public code repositories for exposed credentials.[2]

EnterpriseT1136.003Cloud AccountSub-technique

LAPSUS$ has created global admin accounts in the targeted organization's cloud instances to gain persistence.[2]

EnterpriseT1114.003Email Forwarding RuleSub-technique

LAPSUS$ has set an Office 365 tenant level mail transport rule to send all mail in and out of the targeted organization to the newly created account.[2]

EnterpriseT1591.002Business RelationshipsSub-technique

LAPSUS$ has gathered detailed knowledge of an organization's supply chain relationships.[2]

EnterpriseT1578.003Delete Cloud InstanceSub-technique

LAPSUS$ has deleted the target's systems and resources in the cloud to trigger the organization's incident and crisis response process.[2]

EnterpriseT1555.003Credentials from Web BrowsersSub-technique

LAPSUS$ has obtained passwords and session tokens with the use of the Redline password stealer.[2]

EnterpriseT1531Account Access Removal

LAPSUS$ has removed a targeted organization's global admin accounts to lock the organization out of all access.[2]

EnterpriseT1589.001CredentialsSub-technique

LAPSUS$ has gathered user identities and credentials to gain initial access to a victim's organization; the group has also called an organization's help desk to reset a target's credentials.[2][4]

EnterpriseT1068Exploitation for Privilege Escalation

LAPSUS$ has exploited unpatched vulnerabilities on internally accessible servers including JIRA, GitLab, and Confluence for privilege escalation.[2]

EnterpriseT1621Multi-Factor Authentication Request Generation

LAPSUS$ has spammed target users with MFA prompts in the hope that the legitimate user will grant necessary approval.[2]

EnterpriseT1098.003Additional Cloud RolesSub-technique

LAPSUS$ has added the global admin role to accounts they have created in the targeted organization's cloud instances.[2]

EnterpriseT1003.006DCSyncSub-technique

LAPSUS$ has used DCSync attacks to gather credentials for privilege escalation routines.[2]

EnterpriseT1586.002Email AccountsSub-technique

LAPSUS$ has payed employees, suppliers, and business partners of target organizations for credentials.[2][4]

EnterpriseT1213.005Messaging ApplicationsSub-technique

LAPSUS$ has searched a victim's network for organization collaboration channels like MS Teams or Slack to discover further high-privilege account credentials.[2]

EnterpriseT1589.002Email AddressesSub-technique

LAPSUS$ has gathered employee email addresses, including personal accounts, for social engineering and initial access efforts.[2]

EnterpriseT1584.002DNS ServerSub-technique

LAPSUS$ has reconfigured a victim's DNS records to actor-controlled domains and websites.[4]

EnterpriseT1684.001ImpersonationSub-technique

LAPSUS$ has called victims' help desk and impersonated legitimate users with previously gathered information in order to gain access to privileged accounts.[2]

EnterpriseT1003.003NTDSSub-technique

LAPSUS$ has used Windows built-in tool `ntdsutil` to extract the Active Directory (AD) database.[2]

EnterpriseT1555.005Password ManagersSub-technique

LAPSUS$ has accessed local password managers and databases to obtain further credentials from a compromised network.[4]

EnterpriseT1199Trusted Relationship

LAPSUS$ has accessed internet-facing identity providers such as Azure Active Directory and Okta to target specific organizations.[2]

EnterpriseT1597.002Purchase Technical DataSub-technique

LAPSUS$ has purchased credentials and session tokens from criminal underground forums.[2]

EnterpriseT1578.002Create Cloud InstanceSub-technique

LAPSUS$ has created new virtual machines within the target's cloud environment after leveraging credential access to cloud assets.[2]

EnterpriseT1078.004Cloud AccountsSub-technique

LAPSUS$ has used compromised credentials to access cloud assets within a target organization.[2]

EnterpriseT1111Multi-Factor Authentication Interception

LAPSUS$ has replayed stolen session token and passwords to trigger simple-approval MFA prompts in hope of the legitimate user will grant necessary approval.[2]

Associated objects

Groups, software, and campaigns

ToolEnterprise

S0002: Mimikatz

Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that make it useful for testing the security of networks. [1] [2]

Windows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.1
Created
Modified
Raw hash
9885c79538811205...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.12.1Current bundle9885c7953881…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    BBC LAPSUS Apr 2022

    BBC. (2022, April 1). LAPSUS: Two UK Teenagers Charged with Hacking for Gang. Retrieved June 9, 2022.

    Open source URL
  2. [2]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  3. [3]
    UNIT 42 LAPSUS Mar 2022

    UNIT 42. (2022, March 24). Threat Brief: Lapsus$ Group. Retrieved May 17, 2022.

    Open source URL
  4. [4]
    NCC Group LAPSUS Apr 2022

    Brown, D., et al. (2022, April 28). LAPSUS$: Recent techniques, tactics and procedures. Retrieved December 22, 2022.

    Open source URL
  5. [5]
    BBC LAPSUS Apr 2022

    BBC. (2022, April 1). LAPSUS: Two UK Teenagers Charged with Hacking for Gang. Retrieved June 9, 2022.

    Open source URL
  6. [6]
    BBC LAPSUS Apr 2022

    BBC. (2022, April 1). LAPSUS: Two UK Teenagers Charged with Hacking for Gang. Retrieved June 9, 2022.

    Open source URL
  7. [7]
    DEV-0537

    (Citation: MSTIC DEV-0537 Mar 2022)

  8. [8]
    DEV-0537

    (Citation: MSTIC DEV-0537 Mar 2022)

  9. [9]
    DEV-0537

    (Citation: MSTIC DEV-0537 Mar 2022)

  10. [10]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  11. [11]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  12. [12]
    Microsoft Threat Actor Naming July 2023

    Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.

    Open source URL
  13. [13]
    Microsoft Threat Actor Naming July 2023

    Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.

    Open source URL
  14. [14]
    Microsoft Threat Actor Naming July 2023

    Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.

    Open source URL
  15. [15]
    Strawberry Tempest

    (Citation: Microsoft Threat Actor Naming July 2023)

  16. [16]
    Strawberry Tempest

    (Citation: Microsoft Threat Actor Naming July 2023)

  17. [17]
    Strawberry Tempest

    (Citation: Microsoft Threat Actor Naming July 2023)

  18. [18]
    UNIT 42 LAPSUS Mar 2022

    UNIT 42. (2022, March 24). Threat Brief: Lapsus$ Group. Retrieved May 17, 2022.

    Open source URL
  19. [19]
    UNIT 42 LAPSUS Mar 2022

    UNIT 42. (2022, March 24). Threat Brief: Lapsus$ Group. Retrieved May 17, 2022.

    Open source URL
  20. [20]
    mitre-attackG1004
    Open source URL
  21. [21]
    mitre-attackG1004
    Open source URL
  22. [22]
    mitre-attackG1004
    Open source URL
  23. [23]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  24. [24]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  25. [25]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  26. [26]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  27. [27]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  28. [28]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  29. [29]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  30. [30]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  31. [31]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  32. [32]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  33. [33]
    NCC Group LAPSUS Apr 2022

    Brown, D., et al. (2022, April 28). LAPSUS$: Recent techniques, tactics and procedures. Retrieved December 22, 2022.

    Open source URL
  34. [34]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  35. [35]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  36. [36]
    NCC Group LAPSUS Apr 2022

    Brown, D., et al. (2022, April 28). LAPSUS$: Recent techniques, tactics and procedures. Retrieved December 22, 2022.

    Open source URL
  37. [37]
    NCC Group LAPSUS Apr 2022

    Brown, D., et al. (2022, April 28). LAPSUS$: Recent techniques, tactics and procedures. Retrieved December 22, 2022.

    Open source URL
  38. [38]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  39. [39]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  40. [40]
    NCC Group LAPSUS Apr 2022

    Brown, D., et al. (2022, April 28). LAPSUS$: Recent techniques, tactics and procedures. Retrieved December 22, 2022.

    Open source URL
  41. [41]
    NCC Group LAPSUS Apr 2022

    Brown, D., et al. (2022, April 28). LAPSUS$: Recent techniques, tactics and procedures. Retrieved December 22, 2022.

    Open source URL
  42. [42]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  43. [43]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  44. [44]
    NCC Group LAPSUS Apr 2022

    Brown, D., et al. (2022, April 28). LAPSUS$: Recent techniques, tactics and procedures. Retrieved December 22, 2022.

    Open source URL
  45. [45]
    NCC Group LAPSUS Apr 2022

    Brown, D., et al. (2022, April 28). LAPSUS$: Recent techniques, tactics and procedures. Retrieved December 22, 2022.

    Open source URL
  46. [46]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  47. [47]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  48. [48]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  49. [49]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  50. [50]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  51. [51]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  52. [52]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  53. [53]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  54. [54]
    NCC Group LAPSUS Apr 2022

    Brown, D., et al. (2022, April 28). LAPSUS$: Recent techniques, tactics and procedures. Retrieved December 22, 2022.

    Open source URL
  55. [55]
    NCC Group LAPSUS Apr 2022

    Brown, D., et al. (2022, April 28). LAPSUS$: Recent techniques, tactics and procedures. Retrieved December 22, 2022.

    Open source URL
  56. [56]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  57. [57]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  58. [58]
    NCC Group LAPSUS Apr 2022

    Brown, D., et al. (2022, April 28). LAPSUS$: Recent techniques, tactics and procedures. Retrieved December 22, 2022.

    Open source URL
  59. [59]
    NCC Group LAPSUS Apr 2022

    Brown, D., et al. (2022, April 28). LAPSUS$: Recent techniques, tactics and procedures. Retrieved December 22, 2022.

    Open source URL
  60. [60]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  61. [61]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  62. [62]
    NCC Group LAPSUS Apr 2022

    Brown, D., et al. (2022, April 28). LAPSUS$: Recent techniques, tactics and procedures. Retrieved December 22, 2022.

    Open source URL
  63. [63]
    NCC Group LAPSUS Apr 2022

    Brown, D., et al. (2022, April 28). LAPSUS$: Recent techniques, tactics and procedures. Retrieved December 22, 2022.

    Open source URL
  64. [64]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  65. [65]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  66. [66]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  67. [67]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  68. [68]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  69. [69]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  70. [70]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  71. [71]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  72. [72]
    NCC Group LAPSUS Apr 2022

    Brown, D., et al. (2022, April 28). LAPSUS$: Recent techniques, tactics and procedures. Retrieved December 22, 2022.

    Open source URL
  73. [73]
    NCC Group LAPSUS Apr 2022

    Brown, D., et al. (2022, April 28). LAPSUS$: Recent techniques, tactics and procedures. Retrieved December 22, 2022.

    Open source URL
  74. [74]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  75. [75]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  76. [76]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  77. [77]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  78. [78]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  79. [79]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  80. [80]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  81. [81]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  82. [82]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  83. [83]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  84. [84]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  85. [85]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  86. [86]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  87. [87]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  88. [88]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  89. [89]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  90. [90]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  91. [91]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  92. [92]
    NCC Group LAPSUS Apr 2022

    Brown, D., et al. (2022, April 28). LAPSUS$: Recent techniques, tactics and procedures. Retrieved December 22, 2022.

    Open source URL
  93. [93]
    NCC Group LAPSUS Apr 2022

    Brown, D., et al. (2022, April 28). LAPSUS$: Recent techniques, tactics and procedures. Retrieved December 22, 2022.

    Open source URL
  94. [94]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  95. [95]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  96. [96]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  97. [97]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  98. [98]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  99. [99]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  100. [100]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  101. [101]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  102. [102]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  103. [103]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  104. [104]
    NCC Group LAPSUS Apr 2022

    Brown, D., et al. (2022, April 28). LAPSUS$: Recent techniques, tactics and procedures. Retrieved December 22, 2022.

    Open source URL
  105. [105]
    NCC Group LAPSUS Apr 2022

    Brown, D., et al. (2022, April 28). LAPSUS$: Recent techniques, tactics and procedures. Retrieved December 22, 2022.

    Open source URL
  106. [106]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  107. [107]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  108. [108]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  109. [109]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  110. [110]
    NCC Group LAPSUS Apr 2022

    Brown, D., et al. (2022, April 28). LAPSUS$: Recent techniques, tactics and procedures. Retrieved December 22, 2022.

    Open source URL
  111. [111]
    NCC Group LAPSUS Apr 2022

    Brown, D., et al. (2022, April 28). LAPSUS$: Recent techniques, tactics and procedures. Retrieved December 22, 2022.

    Open source URL
  112. [112]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  113. [113]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  114. [114]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  115. [115]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  116. [116]
    NCC Group LAPSUS Apr 2022

    Brown, D., et al. (2022, April 28). LAPSUS$: Recent techniques, tactics and procedures. Retrieved December 22, 2022.

    Open source URL
  117. [117]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  118. [118]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  119. [119]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  120. [120]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  121. [121]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.