TLP:CLEAR
// Threat Actor Profile — eCrime Extortion Collective / Social-Engineering & Data-Theft Specialist

LAPSUS$

PROFILE COMPILED: 2026-08-30  |  PREVIOUSLY COMPILED: 2026-08-29  |  SOURCES: MITRE ATT&CK, Microsoft MSTIC, CISA Cyber Safety Review Board, Krebs on Security, Resecurity, Mandiant, City of London Police court record, Splunk Security Content, MITRE CTID, Atomic Red Team, SigmaHQ, 10+ additional vendor/press sources
Status: ACTIVE — RESURGENT (2026)
Threat Level: HIGH
Primary Motive: Financial Extortion & Notoriety
Active Since: Mid-2021
MITRE ATT&CK: G1004
⚡ THREAT UPDATE — AUG 2026
Scattered LAPSUS$ Hunters resurgence — active extortion campaign despite 2025 law-enforcement action
Following UK arrests of a suspected key member and associate (Sep 2025) and a joint US/French seizure of extortion-site and BreachForums infrastructure (Oct 2025), the LAPSUS$ brand has re-emerged in 2026 as part of the "Scattered LAPSUS$ Hunters" collective — a public alliance combining LAPSUS$, Scattered Spider, and ShinyHunters branding and tradecraft. The collective is actively claiming victims in 2026, asserting theft of 60M+ records from organizations including SoundCloud, Betterment, Crunchbase, and Match Group (Resecurity, CYFIRMA, Aug 2026). Claimed scope is not independently verified and should be treated with caution consistent with the group's documented history of exaggerating breach impact for extortion leverage.
10+
Household-Name Enterprises Breached, 2021–22 Flagship Campaign
190GB
Samsung Source Code & Biometric Algorithm Data Exfiltrated
71,000+
Nvidia Employee Credentials Stolen
60M+
Records Claimed by Successor Brand "Scattered LAPSUS$ Hunters," 2026
00
Overview

LAPSUS$ is a loosely organized, financially and reputation-motivated eCrime extortion collective, first observed in mid-2021, that became one of the most disruptive threat actors of 2022 despite relying almost entirely on social engineering rather than custom malware or zero-day exploits. In under six months it publicly breached Microsoft, Nvidia, Samsung, Okta, Vodafone, Ubisoft, T-Mobile, Uber, and Rockstar Games (Krebs on Security; Microsoft MSTIC, Mar–Apr 2022), stealing source code, employee credentials, and internal data, and using the threat of public leak — not ransomware encryption — as its extortion lever. Core members, several of them minors based in the UK and Brazil, were identified and prosecuted by 2023, yet the tradecraft and brand did not die with the arrests.

LAPSUS$ matters now because it functions less as a single static group and more as a durable playbook and brand within a broader, largely English-speaking cybercriminal ecosystem known as "The Com." Its signature techniques — help-desk vishing to reset credentials, MFA-prompt bombing, and recruitment of insiders and contractors via direct payment offers — were subsequently adopted near-verbatim by Scattered Spider (UNC3944) in the 2023 MGM/Caesars casino intrusions and the 2025 UK retail attacks against Marks & Spencer, Co-op, and Harrods, illustrating rapid TTP diffusion across affiliated clusters (Resecurity, Aug 2025). In 2025–2026, remnants and affiliates of LAPSUS$ merged branding with Scattered Spider and ShinyHunters to form "Scattered LAPSUS$ Hunters," which remains active as of this writing despite a wave of arrests and infrastructure seizures in late 2025.

Operationally, the group's defining characteristic is that it consistently defeated some of the best-resourced security organizations in the world (Microsoft, Okta, Nvidia) using techniques any mature identity and access management program should be able to detect or prevent — MFA fatigue, help-desk impersonation, and purchased or leaked credentials — rather than sophisticated exploitation. This makes LAPSUS$ and its successor collectives a disproportionate risk indicator for organizational identity-hygiene and third-party/BPO access-control maturity rather than a purely technical detection problem.

01
Identity & Attribution
Primary NameLAPSUS$
Sponsor / ParentNone identified — independent criminal collective, loosely affiliated with "The Com"
Actor TypeeCrime — Extortion / Data-Theft Collective
Primary MotivationFinancial extortion and community notoriety/status (mixed motive, per CISA CSRB)
Active SinceMid-2021 (first confirmed intrusions, Brazil/Portugal)
Last Observed2026 — active under "Scattered LAPSUS$ Hunters" branding
MITRE G-IDG1004
Legal StatusMultiple prosecutions; core UK members convicted 2023; further arrests Sep 2025
Tracking Aliases
LAPSUS$ DEV-0537 (Microsoft, legacy) Strawberry Tempest (Microsoft, current taxonomy) G1004 (MITRE ATT&CK) Scattered LAPSUS$ Hunters (2025–26 successor brand)
Attribution Confidence

[HIGH] confidence that the 2021–2022 LAPSUS$ core was a loosely organized, non-state-sponsored collective of young hackers based principally in the UK and Brazil — supported by City of London Police arrests (Mar 2022) and a seven-week Southwark Crown Court trial that convicted two UK teenagers, including alleged ringleader Arion Kurtaj (BleepingComputer; The Register, 2023). [MEDIUM] confidence regarding continuity between that original core and the 2025–2026 "Scattered LAPSUS$ Hunters" brand — vendor reporting (Resecurity, DataBreach.io) treats the latter as a rebrand/alliance of personas across LAPSUS$, Scattered Spider, and ShinyHunters rather than a confirmed reconstitution of the original membership; law enforcement has not publicly confirmed specific individual overlap.

02
Campaign & Operational Timeline
MID–LATE 2021
Formation & Early Intrusions
First confirmed activity against Brazil's Ministry of Health and Portuguese media conglomerate Impresa, establishing the group's early pattern of high-profile, publicity-driven targeting outside the US/UK before expanding globally (Picus Security; Wikipedia, compiled 2026).
JAN 2022
Okta Supply-Chain Compromise
Gained remote control of a workstation belonging to a support engineer at Sitel, an Okta sub-processor, for approximately 25 minutes, viewing limited Okta customer-support data via Slack and Jira; disclosed publicly only in March 2022 via leaked screenshots (TechCrunch, Mar 2022).
FEB 2022
Nvidia Breach & Extortion Demand
Exfiltrated over 1TB of data including source code, GPU driver documentation, and NTLM hashes for 71,000+ employees; demanded Nvidia remove its Lightweight Hash Rate (LHR) mining limiter and open-source GPU drivers. Nvidia counter-attacked the actors' own systems; LAPSUS$ released an 18GB dump regardless (The Hacker News; BankInfoSecurity, Mar 2022).
MAR 2022
Peak Campaign — Samsung, Microsoft, Vodafone, Ubisoft
Leaked 190GB (402GB unzipped) of Samsung data including Galaxy bootloader source, TrustZone Trusted Applet code, and biometric unlock algorithms; separately breached Microsoft's internal Azure DevOps server and leaked 37GB of source code for Bing, Cortana, and other products via a compromised employee account (AppleInsider; Microsoft MSTIC, Mar 2022).
MAR 2022
UK Law Enforcement Takedown
City of London Police arrested seven individuals aged 16–21 in connection with the group's activity; Arion Kurtaj and a 17-year-old co-defendant were subsequently charged (TechCrunch, Apr 2022).
APR 2022
T-Mobile Breach
Used T-Mobile VPN credentials purchased on the dark web to access the "Atlas" customer-account management tool and internal Slack and Bitbucket, downloading over 30,000 source-code repositories; T-Mobile stated customer PII was not accessed (Krebs on Security, Apr 2022).
SEP 2022
Uber & Rockstar Games Breaches
An affiliated actor used stolen contractor credentials and an MFA-fatigue attack to breach Uber, accessing Slack, Google Workspace, and AWS (BleepingComputer, Sep 2022). Days later, Arion Kurtaj — while on bail and using only a hotel-room Amazon Fire TV Stick, phone, and keyboard — accessed Rockstar Games' Slack and cloud storage to leak early Grand Theft Auto VI gameplay footage (TechRadar, 2023).
AUG–DEC 2023
Convictions & Sentencing
A seven-week trial at Southwark Crown Court found Arion Kurtaj (assessed unfit to stand trial due to autism) responsible for the Rockstar, Uber, and other hacks; he was sentenced to indefinite detention in a secure hospital. A second, then-17-year-old defendant was separately convicted (BleepingComputer; The Register, 2023).
SEP–OCT 2025
Second-Wave Disruption
UK authorities arrested a 19-year-old suspected key member and an associate (Sep 2025). In October 2025, a joint US/French law-enforcement operation seized the group's extortion leak site and portions of BreachForums infrastructure, displaying a joint seizure notice (DataBreach.io, 2025).
2026 — ONGOING
"Scattered LAPSUS$ Hunters" Resurgence
Despite the 2025 disruption, LAPSUS$-affiliated actors rebuilt operational footing under a combined "Scattered LAPSUS$ Hunters" brand with Scattered Spider and ShinyHunters, building on a mid-2025 Salesforce data-theft campaign against 91 organizations and claiming, as of Aug 2026, over 60 million breached records from victims including SoundCloud, Betterment, Crunchbase, and Match Group (Resecurity; CYFIRMA, 2026).
03
Attack Lifecycle Human-driven access acquisition over custom malware

Entry vectors. LAPSUS$ almost never relies on exploit development. Its preferred entry points are: (1) commodity infostealer logs (chiefly RedLine Stealer) purchased or scraped from underground marketplaces, containing already-valid VPN, Citrix, and SSO session credentials; (2) direct recruitment of insiders, contractors, and BPO/help-desk staff via public Telegram ads offering payment for VPN or remote-access credentials; and (3) telephone- and chat-based social engineering of an organization's own IT help desk, impersonating an employee to trigger a password or MFA reset (CISA CSRB, Aug 2023; Microsoft MSTIC, Mar 2022). The Okta (via Sitel) and Uber (via an EXT contractor) intrusions are direct examples of the BPO/contractor vector; T-Mobile and Nvidia are examples of the purchased-credential vector.

Toolchain & C2. The group is notable for its almost total absence of bespoke malware. Post-access, operators use Mimikatz and native Windows utilities (ntdsutil, ntds.dit extraction via DCSync) to dump domain credentials, and the legitimate Sysinternals utility AD Explorer to enumerate Active Directory for privileged accounts. Command-and-control is achieved not through custom implants but through legitimate remote-access software (e.g., AnyDesk) and direct interactive logon with stolen credentials, which blends with normal administrative activity and defeats malware-signature-based defenses.

Lateral movement & persistence. Once inside, the group systematically targets internal collaboration and development platforms — SharePoint, Confluence, Jira, Slack, Microsoft Teams, GitHub, and Bitbucket — searching for hardcoded credentials, API keys, and secrets that enable movement to higher-value systems (Microsoft MSTIC, Mar 2022). Where cloud tenant administrative access (Azure AD/Microsoft 365 or AWS) is obtained, LAPSUS$'s signature persistence move is to create a new Global Administrator account, add a tenant-wide mail transport rule forwarding all inbound and outbound mail to that account, and then remove every other legitimate Global Admin — achieving sole, durable control of the tenant and locking out the victim's own IT staff.

Exfiltration & extortion. Data is exfiltrated directly via bulk downloads from the compromised collaboration and code-repository platforms (e.g., 30,000+ Bitbucket repositories at T-Mobile) rather than through covert channels. LAPSUS$ does not deploy ransomware to encrypt victim data; its leverage is purely the threat — and follow-through — of public release via its Telegram channel, combined in several cases with destructive actions (deleting victim systems/resources) once extortion demands are rejected or access is revoked, consistent with T1485/T1490 impact behavior.

04
TTPs — MITRE ATT&CK Mapping Enterprise ATT&CK — G1004
Reconnaissance
T1589.001
Gather Victim Identity Info: Credentials
[HIGH] Purchases or harvests employee credentials and phone numbers from criminal marketplaces and stealer-log traders prior to intrusion (CISA CSRB, 2023).
Reconnaissance
T1591.002
Gather Victim Org Info: Business Relationships
[HIGH] Mapped target help-desk workflows and BPO/supply-chain relationships (e.g., Okta↔Sitel) to identify the weakest link for access (Microsoft MSTIC, 2022).
Initial Access
T1656
Impersonation
[HIGH] Impersonated employees in phone/chat contact with help desks to socially engineer password and MFA resets (CISA CSRB, 2023).
Initial Access
T1078
Valid Accounts
[HIGH] Authenticated with purchased/leaked VPN and SSO credentials (T-Mobile Atlas access via dark-web-purchased VPN creds) rather than exploiting vulnerabilities.
Credential Access
T1621
Multi-Factor Authentication Request Generation
[HIGH] MFA-fatigue/prompt-bombing against Uber and Microsoft targets until an exhausted user approved a push request.
Credential Access
T1003.006
OS Credential Dumping: DCSync
[HIGH] Used ntdsutil/Mimikatz to perform DCSync, replicating AD password hashes from a domain controller.
Credential Access
T1552.001
Unsecured Credentials: Credentials In Files
[HIGH] Used AD Explorer to search SharePoint, Confluence, Jira, and code repos for hardcoded secrets and additional credentials.
Persistence
T1136.003
Create Account: Cloud Account
[HIGH] Created new Global Administrator accounts inside compromised Azure AD/Microsoft 365 tenants for durable control.
Persistence
T1098.003
Account Manipulation: Additional Cloud Roles
[HIGH] Granted attacker-controlled accounts Global Admin permissions across cloud tenants (Microsoft MSTIC, 2022).
Defense Evasion / Impact
T1531
Account Access Removal
[HIGH] Removed all pre-existing legitimate Global Admin accounts after seizing tenant control, locking out victim IT staff.
Lateral Movement
T1133
External Remote Services
[HIGH] Used stolen VPN/Citrix access to move into corporate networks as an apparently legitimate remote user.
Collection
T1114.003
Email Collection: Email Forwarding Rule
[HIGH] Configured tenant-wide O365 mail-transport rules forwarding all in/outbound mail to attacker-controlled mailboxes.
Collection
T1213.003
Data from Information Repositories: Code Repositories
[HIGH] Bulk-downloaded 30,000+ source repositories from T-Mobile's Bitbucket; 37GB from Microsoft's Azure DevOps.
Command & Control
T1219
Remote Access Software
[MEDIUM] Installed commercial remote-desktop tools (e.g., AnyDesk) for hands-on-keyboard access that blends with legitimate admin traffic.
Impact
T1485
Data Destruction
[MEDIUM] Reported deletion of victim systems/cloud resources following failed extortion or after access was revoked.
Impact
T1657
Financial Theft
[HIGH] Leak-site publication threats used as direct extortion leverage against victims in lieu of ransomware encryption.
05
Targeting Profile
Sector Targeting
Technology / Software
PRIMARY
Telecommunications
HIGH
BPO / IT-Managed Service Providers
HIGH
Media & Gaming
MED
Government
MED
Financial Services / Fintech
LOW
GeographiesPrimarily US and UK targets from 2022 onward; earliest activity in Brazil and Portugal; global reach under the 2025–26 successor brand.
Victim ProfileLarge, brand-name organizations with high public profile and valuable IP, source code, or PII — ranging from mid-size BPOs (Sitel) to trillion-dollar technology firms (Microsoft, Nvidia, Samsung).
Preferred EntryThird-party/BPO help-desk and contractor access; purchased or leaked VPN/remote-access credentials from criminal marketplaces; direct insider recruitment via Telegram payment offers.
Target DoctrineOpportunistic, notoriety-driven selection of household-name targets for maximum extortion leverage and reputational impact, rather than a fixed target list.
06
Tools, Malware & Infrastructure
REDLINE STEALER COTS INFOSTEALER · T1555 / T1539
Commodity, subscription-based infostealer purchased on cybercrime marketplaces (not developed by LAPSUS$). Harvests browser-stored passwords, session/authentication cookies, cryptocurrency wallets, and VPN client credentials, exfiltrating logs to operator-controlled infrastructure. LAPSUS$ used bulk RedLine logs — including a documented LATAM-focused campaign — to source the valid credentials that seeded several intrusions (Metabase Q, 2022).
MIMIKATZ CREDENTIAL DUMPER · T1003.001
Well-known open-source post-exploitation utility used to extract plaintext passwords, NTLM hashes, and Kerberos tickets from LSASS memory once a foothold with sufficient privilege was established, enabling escalation to domain-level access (Vectra AI, 2022).
AD EXPLORER (SYSINTERNALS) LOLBIN — LEGITIMATE ADMIN TOOL · T1087.002 / T1213
Legitimate Microsoft Sysinternals Active Directory viewer/search utility, repurposed to enumerate privileged accounts and group memberships, and to search internal collaboration platforms (SharePoint, Confluence, Jira, GitHub) for hardcoded secrets — evading detections tuned for malicious tooling since the binary itself is trusted.
NTDSUTIL / DCSYNC NATIVE WINDOWS UTILITY · T1003.006
Native Windows administrative utility abused to perform directory-replication (DCSync) requests, pulling password hashes for all domain accounts from a domain controller without requiring code execution on the DC itself — a technique that is difficult to distinguish from legitimate replication traffic without dedicated monitoring.
ANYDESK / COMMERCIAL REMOTE-ACCESS SOFTWARE LOLBIN — LEGITIMATE RMM TOOL · T1219
Commercial remote-desktop software installed post-compromise to sustain hands-on-keyboard access. Traffic blends with legitimate IT administrative activity, and the tool's dual-use nature means allow-listed or unmonitored deployments provide durable, low-visibility access.
TELEGRAM (VICTIM COMMS / LEAK CHANNEL) INFRASTRUCTURE — 3RD-PARTY PLATFORM · T1102
Public Telegram channel used as the group's primary extortion, negotiation, and leak-publication venue, and as a recruitment board advertising direct payment to employees/contractors of named target organizations in exchange for VPN or remote-access credentials — an insider-recruitment vector distinct from technical intrusion.
07
Indicators of Compromise Behavioral indicators predominate — see note below
⚠ IOC HANDLING — All IPs and domains in this table are defanged. Reconstruct before use in detection tooling. Reference URLs in Section 10 are NOT defanged.
Type Value / Description Source Date
NOTENo persistent, publicly attributable C2 IP addresses, domains, or malware file hashes are durably associated with LAPSUS$ core operations as of 2026-08-29. The group relies on commodity stealer logs, purchased/leaked credentials, and living-off-the-land or legitimate remote-access tooling rather than fixed, custom infrastructure — consistent with CISA CSRB's finding that the group used "primarily simple techniques."CISA CSRB2023-08-10
BEHAVIORBurst of 10+ MFA push notifications to a single user within minutes, often outside normal business hours ("MFA fatigue" / prompt-bombing pattern)Microsoft MSTIC2022-03-22
BEHAVIORHelp-desk contact requesting password or MFA-method reset for a privileged account without standard out-of-band identity verificationCISA CSRB2023-08-10
BEHAVIORNew Global Administrator account created in an Azure AD / Microsoft 365 tenant, followed shortly by removal of pre-existing Global Admin accountsMicrosoft MSTIC2022-03-22
BEHAVIORNew Exchange Online mail-transport/forwarding rule created that routes all inbound and outbound mail to an external or newly created mailboxMicrosoft MSTIC2022-03-22
BEHAVIORBulk, scripted-pattern cloning or download activity against source-code repositories (Bitbucket / GitHub / Confluence / Jira) from a single account within a short time windowKrebs on Security2022-04-22
PROTOCOLOutbound sessions to consumer/commercial remote-access software domains (e.g., AnyDesk) initiated from privileged administrative workstations shortly after anomalous authenticationNCC Group2022
PROTOCOLDirectory-replication (DCSync-pattern) LDAP/RPC requests to a domain controller originating from a non-domain-controller hostVectra AI2022
08
Analyst Assessment
Overall Threat LevelHIGH
Attribution ConfidenceHIGH (2021–22 core) / MEDIUM (2025–26 continuity)
TrajectoryEscalating — active resurgence under Scattered LAPSUS$ Hunters brand
Most Dangerous CapabilityHelp-desk social engineering + MFA-fatigue chain for privileged access acquisition
Primary Intel GapVerified membership overlap between original LAPSUS$ core and the 2025–26 successor brand; true scale of 2026 breach claims
Ecosystem / Affiliated Groups
Scattered Spider / UNC3944 ShinyHunters The Com (umbrella community) Scattered LAPSUS$ Hunters (2025–26 alliance brand)

LAPSUS$'s core significance is that it demonstrated — repeatedly, against some of the best-resourced security organizations in the world — that unsophisticated, socially engineered tradecraft executed quickly and without regard for operational security could outpace technically sophisticated ransomware crews. [HIGH] confidence assessment, grounded in UK court proceedings against Arion Kurtaj and a co-defendant, is that the operational core was young (several members minors), UK/Brazil-based, and motivated by a mixed blend of financial gain and community status within "The Com" rather than financial gain alone — a profile the CISA Cyber Safety Review Board explicitly flagged as complicating deterrence, since notoriety-seeking actors are less responsive to purely financial disincentives.

The group's most dangerous capability is not any piece of malware but its help-desk-vishing-plus-MFA-fatigue chain for acquiring privileged access, which exploits human and process trust rather than a technical control gap, leaving conventional endpoint and network defenses with limited direct purchase on the initial-access stage. This exact playbook has since proliferated well beyond LAPSUS$ itself — most visibly in Scattered Spider's near-identical help-desk vishing campaigns against MGM and Caesars (2023) and the 2025 UK retail wave (M&S, Co-op, Harrods) — which raises a competing hypothesis worth stating explicitly: it is not yet established whether Scattered Spider directly learned this tradecraft from LAPSUS$ operators, or whether both groups independently converged on the same techniques as a natural product of shared origin within the same underground forums and Discord/Telegram communities. [MEDIUM] confidence is assigned to a direct tradecraft lineage rather than parallel evolution.

On forward trajectory: the emergence of "Scattered LAPSUS$ Hunters" in 2025–2026 — persisting despite UK arrests (Sep 2025) and a joint US/French seizure of extortion-site and BreachForums infrastructure (Oct 2025) — demonstrates that arrests of individual members do not reliably kill the underlying brand or tradecraft within Com-affiliated collectives; the community, playbook, and "brand equity" of the LAPSUS$ name outlive any specific defendant. [LOW–MEDIUM] confidence should be placed on the raw scale of 2026 claims (e.g., "60 million records," the earlier "91 organizations" Salesforce-campaign figure) absent independent victim confirmation, consistent with the group's established pattern of inflating breach scope for extortion leverage — Okta's confirmed impact of two customer tenants versus LAPSUS$'s initial public claims of a much broader compromise is the clearest historical precedent for this gap. What would raise attribution confidence for the 2025–26 continuity question: law-enforcement charging documents or forensic overlap (shared infrastructure, negotiation writing style, or leak-site TTPs) explicitly tying named 2025–26 arrestees to verified 2021–22 LAPSUS$ core membership.

09
Defensive Recommendations
01
Deploy phishing-resistant MFA. Replace push- and SMS-based MFA with FIDO2/WebAuthn hardware security keys for all privileged, remote-access, and help-desk-facing accounts.
Counters: T1621, T1078
02
Eliminate raw push-approval MFA. Where hardware keys are not yet feasible, enforce number-matching and context-rich (location/app-name) push approval to neutralize MFA-fatigue/prompt-bombing.
Counters: T1621
03
Harden help-desk identity verification. Require callback to a pre-registered number, supervisor co-approval, or video verification before any password/MFA reset on a privileged account.
Counters: T1656, T1078
04
Enforce just-in-time privileged access. Remove standing Global Admin/Domain Admin accounts in favor of time-bound, approval-gated privileged access management (PAM), and alert on any new Global Admin creation.
Counters: T1136.003, T1098.003
05
Monitor mail-transport rule changes. Alert in real time on creation of any Exchange Online/O365 transport or forwarding rule matching "all mail" or external-domain forwarding patterns.
Counters: T1114.003
06
Restrict and monitor directory replication. Limit DCSync-capable replication rights to actual domain controllers and alert on replication requests from any other host.
Counters: T1003.006
07
Deploy risk-based conditional access. Block or step-up-challenge authentication from unmanaged devices, impossible-travel geographies, or anonymizing infrastructure even when credentials are valid.
Counters: T1078, T1133
08
Extend controls to third-party/BPO staff. Apply the same identity-verification, MFA, and monitoring requirements to contractor and outsourced help-desk personnel with access to customer-support tooling as to employees.
Counters: T1656, supply-chain initial access
09
Run secrets-scanning on internal repositories. Continuously scan SharePoint, Confluence, Jira, GitHub, and Bitbucket for hardcoded credentials/API keys, and apply least-privilege repository access.
Counters: T1213.003, T1552.001
10
Control remote-access tooling. Allow-list approved RMM/remote-desktop software and alert on installation or use of unauthorized tools (e.g., AnyDesk) on privileged endpoints.
Counters: T1219
10
OPSEC Procedures Observed infrastructure hygiene, rotation patterns, anti-forensics
Infrastructure Rotation [LOW]
No public evidence of a dedicated, self-hosted, or rotating C2 infrastructure footprint. Rather than building and cycling attacker-owned VPS/VPN nodes, LAPSUS$ authenticated through legitimate VPN and remote-access credentials that were purchased, phished, or leaked — meaning the group's network "infrastructure" was, in effect, the victim's own trusted infrastructure. This is consistent with CISA CSRB's finding that the group used "primarily simple techniques" and is itself a notable absence: it removed the usual infrastructure-based detection and attribution surface that IP/domain threat-intel feeds rely on for more traditional actors.
Living-off-the-Land Ratio [HIGH]
Overwhelmingly weighted toward native OS utilities and commercial/open-source dual-use tools over custom malware. Documented toolset is limited to Mimikatz, Sysinternals AD Explorer, native ntdsutil/DCSync replication, and commercial remote-access software (AnyDesk) — no bespoke implant, loader, or C2 framework has been publicly attributed to the group across any of its major intrusions (Microsoft MSTIC, 2022; CISA CSRB, 2023). CSRB explicitly cited this as the group's defining characteristic: high-impact outcomes achieved through "well-known and available" techniques rather than novel tradecraft.
Anti-Forensics / Endpoint-Defense Neutralization [MEDIUM–HIGH]
During the Sitel/Okta intrusion, Mandiant's forensic report documented the actor using ProcessHacker and Process Explorer — both legitimate, publicly-available Windows process/system utilities — specifically to terminate the FireEye endpoint security agent running on the compromised support-engineer workstation, clearing the way for Mimikatz-based credential dumping and privilege escalation. No public reporting reviewed for this compile documents systematic Windows Event Log clearing, timestomping, or memory-only execution discipline beyond this defense-termination step — the group's anti-forensics posture appears narrowly focused on disabling the specific security tool in its way rather than broader forensic-trace suppression.
Timing & Operational Patterns [MEDIUM]
Microsoft MSTIC documented bursts of 10+ MFA push notifications sent to a single target within minutes, in at least one case timed outside the victim's normal business hours to exploit reduced vigilance and a higher likelihood of an exhausted or half-attentive approval. Beyond this specific MFA-fatigue timing pattern, no broader beaconing, jitter, or dwell-time discipline is publicly documented — consistent with an actor executing short, opportunistic access windows (the Okta/Sitel intrusion lasted approximately 25 minutes) rather than sustained, patient long-dwell operations.
Tooling Hygiene [MEDIUM]
No evidence of custom-malware recompilation, hash-evasion, or binary obfuscation practices is documented — because the group's toolkit consists almost entirely of unmodified, legitimately-signed or open-source utilities (Mimikatz, AD Explorer, Process Hacker), it has comparatively little need for the packing/obfuscation hygiene associated with actors running bespoke implants. This is best read as a byproduct of the group's living-off-the-land approach rather than a deliberate anti-detection engineering practice.
Personal & Identity OPSEC (Non-Technical) [HIGH]
This is the single most consequential OPSEC dimension for LAPSUS$ specifically, and it runs opposite to the group's technical tradecraft: personal/identity security was notably poor. A rival doxxed alleged member "White" (subsequently linked in court proceedings to Arion Kurtaj), publishing personal information including age, location, and family details that directly informed the City of London Police investigation (Sekoia, 2022). CSRB's report separately characterized the broader pattern across LAPSUS$ and related groups as reflecting "systemic failures" in both victim organizations' defenses and the actors' own community-facing conduct — public Telegram recruitment, competitive boasting, and in-fighting among members repeatedly generated the investigative leads that led to the March 2022 arrests. The technical living-off-the-land discipline documented above did not extend to the operators' own personal-identity tradecraft.
11
Detection Evasion Specific techniques, LOLBin sequences, EDR bypass patterns
EDR Agent Termination via Process Utilities T1562.001
EDR BYPASS ProcessHacker · Process Explorer
During the Sitel/Okta intrusion, the actor used the legitimate system utilities ProcessHacker and Process Explorer to identify and forcibly terminate the FireEye endpoint detection agent process on the compromised workstation before proceeding to credential dumping — a direct, low-sophistication "impair defenses" step rather than a kernel-level or driver-based EDR bypass (Mandiant forensic report, cited via multiple secondary sources, 2022).
Specific process names, command-line arguments, and exact termination method (GUI interaction vs. scripted) not publicly documented as of 2026-08-30 — reporting confirms the tools used and the outcome (FireEye agent disabled) but not the precise operator commands.
Post-Credential-Dump Escalation via Mimikatz T1003.001
EDR BYPASS Mimikatz
Immediately following EDR agent termination, Mimikatz was used to extract credential material from the now-unmonitored host, enabling privilege escalation — the evasion value here is purely sequential (disable detection, then perform the action detection would otherwise catch) rather than any obfuscation of Mimikatz itself.
Specific Mimikatz module/command invocation (e.g., sekurlsa::logonpasswords vs. other modules) not publicly documented as of 2026-08-30.
Authentication-Anomaly Evasion via MFA-Fatigue Timing T1621
SIEM EVASION
Rather than technically evading MFA telemetry, the group exploited the fact that most SIEM/identity-monitoring configurations of the era did not alert on volume or timing anomalies in MFA push requests — sending 10+ requests to a single user within minutes, in at least one case outside normal working hours, until an exhausted user approved one (Microsoft MSTIC, 2022). This defeats detection built around "was the credential valid" rather than "was this authentication behavior itself anomalous."
No further technical specifics (exact push interval, total request count per incident beyond "10+") publicly documented as of 2026-08-30.
Traffic Blending via Commercial Remote-Access Software T1219
NETWORK EDR BYPASS
Post-compromise use of commercial RMM software (e.g., AnyDesk) generates network traffic and process activity that is difficult to distinguish from legitimate IT-administrator remote support sessions, particularly in environments where such tools are already deployed for helpdesk use — evading both network-based anomaly detection and EDR rules tuned to flag unfamiliar remote-access binaries.
Specific AnyDesk configuration, deployment method, or persistence flags not publicly documented as of 2026-08-30.
12
Emulation Resources MITRE CTID & Published Adversary Emulation Plans
MITRE CTID — NOT AVAILABLE No Adversary Emulation Plan Published
No MITRE Center for Threat-Informed Defense adversary emulation plan has been published for LAPSUS$, its "Strawberry Tempest"/DEV-0537 designation, or the "Scattered LAPSUS$ Hunters" successor brand as of 2026-08-30. The CTID Adversary Emulation Library's current Full Emulation Plans cover APT29, Blind Eagle, Carbanak Group, FIN6, FIN7, menuPass, OceanLotus, OilRig, Sandworm, Turla, and Wizard Spider — no social-engineering-led eCrime collective in the LAPSUS$/Scattered Spider/The Com ecosystem is represented in the library at this time (verified directly against the library's repository listing).
Additional Emulation Resources
Splunk Security Content
Vendor detection lab — 140+ detections spanning MFA manipulation, LSASS dumping, RMM-tool deployment, Kerberos ticket attacks, defense-evasion/security-tool disablement, and cloud-storage exfiltration, mapped to ATT&CK · Accessed: 2026-08-30
Atomic Red Team
Atomic test, directly applicable — DCSync is a documented LAPSUS$ credential-access technique · Accessed: 2026-08-30
Atomic Red Team
Atomic test, directly applicable — mail-transport-rule hijack is a documented LAPSUS$ persistence/collection technique · Accessed: 2026-08-30
Atomic Red Team
Atomic test, directly applicable — MFA-fatigue/push-bombing emulation · Accessed: 2026-08-30
SigmaHQ
Detection rule for directory-replication (DCSync) requests · Accessed: 2026-08-30
SigmaHQ
Detection rule for backdoored DCSync replication rights grants · Accessed: 2026-08-30
RedCanary
Detection guidance mapped to the T1114.003 mail-forwarding-rule technique used by LAPSUS$ · Accessed: 2026-08-30
13
References URLs are NOT defanged — navigate directly
MITRE ATT&CK
Accessed: 2026-08-29
Krebs on Security
Accessed: 2026-08-29
BleepingComputer
Accessed: 2026-08-29
DataBreach.io
Accessed: 2026-08-29
CYFIRMA
Accessed: 2026-08-29
Metabase Q
Accessed: 2026-08-29
Vectra AI
Accessed: 2026-08-29
Sekoia
Accessed: 2026-08-30
Mandiant / Okta Disclosure Coverage
Accessed: 2026-08-30
Splunk
Accessed: 2026-08-30