Advisor

LAPSUS$

1 min read
Jump to:

Summary

LAPSUS$ is a cybercriminal group known for conducting high-profile application attacks, including data breaches and extortion campaigns targeting large technology companies and organizations worldwide. Emerging prominently in 2021 and 2022, the group gained notoriety for exploiting social engineering techniques, account takeovers, and leveraging stolen credentials to access internal systems and exfiltrate sensitive data.

Key Characteristics

  • Use of social engineering and SIM swapping to gain initial access to corporate networks.
  • Targeting of source code repositories, internal tools, and privileged accounts.
  • Public release of stolen data to pressure victims into meeting ransom demands.
  • Rapid dissemination of leaked information across public forums and social media.
  • Focus on high-profile technology firms, telecommunications companies, and government entities.

Defensive Controls

Related Security Solutions

Security solutions relevant to defending against LAPSUS$ activities include identity and access management (IAM) systems, multi-factor authentication platforms, endpoint detection and response (EDR) tools, security information and event management (SIEM) systems, and user behavior analytics (UBA). Additionally, threat intelligence services can provide timely information on emerging tactics and indicators of compromise associated with the group.

Tags: Application Attacks credential theft endpoint detection and response identity and access management LAPSUS$ multi-factor authentication Social Engineering Threats & Attacks