LAPSUS$
G10042 reportsaliases · LAPSUS$ · DEV-0537 · Strawberry Tempest
2
Reports
2
Techniques
2
Tactics
4
Countries
100%
Hunt coverage
3
Aliases
Analyst assessment — key judgments
- Signature techniques: T1684.001 (Impersonation), AML.T0073 (Impersonation).
- Primary targeting: KR, CA, DE, AR.
- Resurgent after a quiet period: 1 report(s) in last 30d vs 0 prior (+100%).
- Hunt coverage 100% of 2 observed techniques (0 gap(s)).
- Assessment confidence: medium (60).
Activity & trend
ResurgentLast 30d: 1 vs 0 prior (+100%)· first reported 2026-06-24 · last 2026-09-09
0
7d
1
30d
2
90d
2
All
0.2
Rpts/wk
Reporting timeline · 12 months
Movement — last 30 days
Targeting gained
ARCADEKROverview
Analyst triage
Intelligence summary
LAPSUS$ is cyber criminal threat group that has been active since at least mid-2021. LAPSUS$ specializes in large-scale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.(Citation: BBC LAPSUS Apr 2022)(Citation: MSTIC DEV-0537 Mar 2022)(Citation: UNIT 42 LAPSUS Mar 2022)
Top co-occurring indicators
Aliases & naming
Targeting · countries
Targeting · named victims
ATT&CK technique matrix
Coverage vs hunt library:
—
Hunt-coverage gaps — prioritized
Top techniques by observation
- T1684.001 · Impersonationconf 601
- AML.T0073 · Impersonationconf 601
Threat catalogue · engineering roadmap
Flagged detection-engineering queue
Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.
Infrastructure
IOC type mix
Tooling / malware families
Relationships
Activity
30-day mention timeline
Recent reporting
| Title | Source | Severity | Collected |
|---|