Threat group.View on attack.mitre.org
LAPSUS$ is cyber criminal threat group that has been active since at least mid-2021. LAPSUS$ specializes in large-scale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.
| Technique | Procedure example |
|---|---|
| T1003.003 NTDS |
LAPSUS$ has used Windows built-in tool `ntdsutil` to extract the Active Directory (AD) database. |
| T1003.006 DCSync |
LAPSUS$ has used DCSync attacks to gather credentials for privilege escalation routines. |
| T1005 Data from Local System |
LAPSUS$ uploaded sensitive files, information, and credentials from a targeted organization for extortion or public release. |
| T1068 Exploitation for Privilege Escalation |
LAPSUS$ has exploited unpatched vulnerabilities on internally accessible servers including JIRA, GitLab, and Confluence for privilege escalation. |
| T1069.002 Domain Groups |
LAPSUS$ has used the AD Explorer tool to enumerate groups on a victim's network. |
| T1078 Valid Accounts |
LAPSUS$ has used compromised credentials and/or session tokens to gain access into a victim's VPN, VDI, RDP, and IAMs. |
| T1078.004 Cloud Accounts |
LAPSUS$ has used compromised credentials to access cloud assets within a target organization. |
| T1087.002 Domain Account |
LAPSUS$ has used the AD Explorer tool to enumerate users on a victim's network. |
| T1090 Proxy |
LAPSUS$ has leverage NordVPN for its egress points when targeting intended victims. |
| T1098.003 Additional Cloud Roles |
LAPSUS$ has added the global admin role to accounts they have created in the targeted organization's cloud instances. |
| T1111 Multi-Factor Authentication Interception |
LAPSUS$ has replayed stolen session token and passwords to trigger simple-approval MFA prompts in hope of the legitimate user will grant necessary approval. |
| T1114.003 Email Forwarding Rule |
LAPSUS$ has set an Office 365 tenant level mail transport rule to send all mail in and out of the targeted organization to the newly created account. |
| T1133 External Remote Services |
LAPSUS$ has gained access to internet-facing systems and applications, including virtual private network (VPN), remote desktop protocol (RDP), and virtual desktop infrastructure (VDI) including Citrix. |
| T1136.003 Cloud Account |
LAPSUS$ has created global admin accounts in the targeted organization's cloud instances to gain persistence. |
| T1199 Trusted Relationship |
LAPSUS$ has accessed internet-facing identity providers such as Azure Active Directory and Okta to target specific organizations. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.