LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G1004: LAPSUS$

LAPSUS$ is cyber criminal threat group that has been active since at least mid-2021. LAPSUS$ specializes in large-scale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.[1][2][3]

EnterpriseG1004GroupObject v2.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

G1004: LAPSUS$ describes [LAPSUS$](https://attack.mitre.org/groups/G1004) is cyber criminal threat group that has been active since at least mid-2021. [LAPSUS$](https://attack.mitre.org/groups/G1004) specializes in large-scale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.(Citation: BBC LAPSUS Apr 2022)(C...

Executive priority

G1004: LAPSUS$ is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate G1004: LAPSUS$ by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata

Detection direction

  • Validate whether G1004: LAPSUS$ appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

LAPSUS$

LAPSUS$ is cyber criminal threat group that has been active since at least mid-2021. LAPSUS$ specializes in large-scale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.[1][2][3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

43 rows
DomainIDNameRelationship / procedure
EnterpriseT1589Gather Victim Identity Information

LAPSUS$ has gathered detailed information of target employees to enhance their social engineering lures.[2]

EnterpriseT1005Data from Local System

LAPSUS$ uploaded sensitive files, information, and credentials from a targeted organization for extortion or public release.[2]

EnterpriseT1069.002Domain GroupsSub-technique

LAPSUS$ has used the AD Explorer tool to enumerate groups on a victim's network.[2]

EnterpriseT1213.001ConfluenceSub-technique

LAPSUS$ has searched a victim's network for collaboration platforms like Confluence and JIRA to discover further high-privilege account credentials.[2]

EnterpriseT1588.002ToolSub-technique

LAPSUS$ has obtained tools such as RVTools and AD Explorer for their operations.[2]CitationNCC Group LAPSUS Apr 2022

EnterpriseT1485Data Destruction

LAPSUS$ has deleted the target's systems and resources both on-premises and in the cloud.[2]CitationNCC Group LAPSUS Apr 2022

EnterpriseT1213.003Code RepositoriesSub-technique

LAPSUS$ has searched a victim's network for code repositories like GitLab and GitHub to discover further high-privilege account credentials.[2]CitationNCC Group LAPSUS Apr 2022

EnterpriseT1213.002SharepointSub-technique

LAPSUS$ has searched a victim's network for collaboration platforms like SharePoint to discover further high-privilege account credentials.[2]CitationNCC Group LAPSUS Apr 2022

EnterpriseT1583.003Virtual Private ServerSub-technique

LAPSUS$ has used VPS hosting providers for infrastructure.[2]

EnterpriseT1591.004Identify RolesSub-technique

LAPSUS$ has gathered detailed knowledge of team structures within a target organization.[2]

EnterpriseT1090Proxy

LAPSUS$ has leverage NordVPN for its egress points when targeting intended victims.[2]

EnterpriseT1087.002Domain AccountSub-technique

LAPSUS$ has used the AD Explorer tool to enumerate users on a victim's network.[2]CitationNCC Group LAPSUS Apr 2022

EnterpriseT1133External Remote Services

LAPSUS$ has gained access to internet-facing systems and applications, including virtual private network (VPN), remote desktop protocol (RDP), and virtual desktop infrastructure (VDI) including Citrix. [2]CitationNCC Group LAPSUS Apr 2022

EnterpriseT1078Valid Accounts

LAPSUS$ has used compromised credentials and/or session tokens to gain access into a victim's VPN, VDI, RDP, and IAMs.[2]CitationNCC Group LAPSUS Apr 2022

EnterpriseT1588.001MalwareSub-technique

LAPSUS$ acquired and used the Redline password stealer in their operations.[2]

EnterpriseT1598.004Spearphishing VoiceSub-technique

LAPSUS$ has called victims' help desk to convince the support personnel to reset a privileged account’s credentials.[2]

EnterpriseT1204User Execution

LAPSUS$ has recruited target organization employees or contractors who provide credentials and approve an associated MFA prompt, or install remote management software onto a corporate workstation, allowing LAPSUS$ to take control of an authenticated system.[2]

EnterpriseT1552.008Chat MessagesSub-technique

LAPSUS$ has targeted various collaboration tools like Slack, Teams, JIRA, Confluence, and others to hunt for exposed credentials to support privilege escalation and lateral movement.[2]

EnterpriseT1489Service Stop

LAPSUS$ has shut down virtual machines from within a victim's on-premise VMware ESXi infrastructure.CitationNCC Group LAPSUS Apr 2022

EnterpriseT1593.003Code RepositoriesSub-technique

LAPSUS$ has searched public code repositories for exposed credentials.[2]

EnterpriseT1136.003Cloud AccountSub-technique

LAPSUS$ has created global admin accounts in the targeted organization's cloud instances to gain persistence.[2]

EnterpriseT1114.003Email Forwarding RuleSub-technique

LAPSUS$ has set an Office 365 tenant level mail transport rule to send all mail in and out of the targeted organization to the newly created account.[2]

EnterpriseT1591.002Business RelationshipsSub-technique

LAPSUS$ has gathered detailed knowledge of an organization's supply chain relationships.[2]

EnterpriseT1578.003Delete Cloud InstanceSub-technique

LAPSUS$ has deleted the target's systems and resources in the cloud to trigger the organization's incident and crisis response process.[2]

EnterpriseT1555.003Credentials from Web BrowsersSub-technique

LAPSUS$ has obtained passwords and session tokens with the use of the Redline password stealer.[2]

EnterpriseT1531Account Access Removal

LAPSUS$ has removed a targeted organization's global admin accounts to lock the organization out of all access.[2]

EnterpriseT1589.001CredentialsSub-technique

LAPSUS$ has gathered user identities and credentials to gain initial access to a victim's organization; the group has also called an organization's help desk to reset a target's credentials.[2]CitationNCC Group LAPSUS Apr 2022

EnterpriseT1068Exploitation for Privilege Escalation

LAPSUS$ has exploited unpatched vulnerabilities on internally accessible servers including JIRA, GitLab, and Confluence for privilege escalation.[2]

EnterpriseT1621Multi-Factor Authentication Request Generation

LAPSUS$ has spammed target users with MFA prompts in the hope that the legitimate user will grant necessary approval.[2]

EnterpriseT1098.003Additional Cloud RolesSub-technique

LAPSUS$ has added the global admin role to accounts they have created in the targeted organization's cloud instances.[2]

EnterpriseT1586.002Email AccountsSub-technique

LAPSUS$ has payed employees, suppliers, and business partners of target organizations for credentials.[2]CitationNCC Group LAPSUS Apr 2022

EnterpriseT1213.005Messaging ApplicationsSub-technique

LAPSUS$ has searched a victim's network for organization collaboration channels like MS Teams or Slack to discover further high-privilege account credentials.[2]

EnterpriseT1589.002Email AddressesSub-technique

LAPSUS$ has gathered employee email addresses, including personal accounts, for social engineering and initial access efforts.[2]

EnterpriseT1584.002DNS ServerSub-technique

LAPSUS$ has reconfigured a victim's DNS records to actor-controlled domains and websites.CitationNCC Group LAPSUS Apr 2022

EnterpriseT1684.001ImpersonationSub-technique

LAPSUS$ has called victims' help desk and impersonated legitimate users with previously gathered information in order to gain access to privileged accounts.[2]

EnterpriseT1003.003NTDSSub-technique

LAPSUS$ has used Windows built-in tool `ntdsutil` to extract the Active Directory (AD) database.[2]

EnterpriseT1555.005Password ManagersSub-technique

LAPSUS$ has accessed local password managers and databases to obtain further credentials from a compromised network.CitationNCC Group LAPSUS Apr 2022

EnterpriseT1199Trusted Relationship

LAPSUS$ has accessed internet-facing identity providers such as Azure Active Directory and Okta to target specific organizations.[2]

EnterpriseT1597.002Purchase Technical DataSub-technique

LAPSUS$ has purchased credentials and session tokens from criminal underground forums.[2]

EnterpriseT1578.002Create Cloud InstanceSub-technique

LAPSUS$ has created new virtual machines within the target's cloud environment after leveraging credential access to cloud assets.[2]

EnterpriseT1078.004Cloud AccountsSub-technique

LAPSUS$ has used compromised credentials to access cloud assets within a target organization.[2]

EnterpriseT1111Multi-Factor Authentication Interception

LAPSUS$ has replayed stolen session token and passwords to trigger simple-approval MFA prompts in hope of the legitimate user will grant necessary approval.[2]

EnterpriseT1003.006DCSyncSub-technique

LAPSUS$ has used DCSync attacks to gather credentials for privilege escalation routines.[2]

Associated objects

Groups, software, and campaigns

ToolEnterprise

S0002: Mimikatz

Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that make it useful for testing the security of networks. [1] [2]

Windows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
2.1
Created
Modified
Raw hash
c704a046302c51ab...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.22.1Current bundlec704a046302c…
19.12.1Older bundle9885c7953881…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    BBC LAPSUS Apr 2022

    BBC. (2022, April 1). LAPSUS: Two UK Teenagers Charged with Hacking for Gang. Retrieved June 9, 2022.

    Open source URL
  2. [2]
    MSTIC DEV-0537 Mar 2022

    MSTIC, DART, M365 Defender. (2022, March 24). DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction. Retrieved May 17, 2022.

    Open source URL
  3. [3]
    UNIT 42 LAPSUS Mar 2022

    UNIT 42. (2022, March 24). Threat Brief: Lapsus$ Group. Retrieved May 17, 2022.

    Open source URL
  4. [4]
    DEV-0537

    (Citation: MSTIC DEV-0537 Mar 2022)

  5. [5]
    Microsoft Threat Actor Naming July 2023

    Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.

    Open source URL
  6. [6]
    Strawberry Tempest

    (Citation: Microsoft Threat Actor Naming July 2023)

  7. [7]
    mitre-attackG1004
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.