LAPSUS$ is a financially motivated cybercriminal extortion group known for high-profile intrusions against major technology, telecommunications, gaming, and identity-management organizations. The group is widely associated with aggressive social engineering, including vishing and impersonation of employees or contractors, as well as insider recruitment and abuse of authentication and identity workflows to obtain initial access. Public reporting and criminal cases have linked LAPSUS$ to a loose youth-centric criminal milieu overlapping with The Com, and some reporting has noted associations or operational overlap with actors such as Scattered Spider and ShinyHunters. Microsoft tracks the group as Strawberry Tempest, and other aliases include DEV-0537 and Slippy Spider. LAPSUS$ has been tied to intrusions and extortion activity affecting organizations such as Nvidia, Microsoft, Samsung, Ubisoft, Okta, BT, Rockstar Games, Vodafone UK, and other prominent targets. The group became notable for stealing sensitive internal data and source code, then publicly pressuring victims through leak channels and victim announcements. Its operations have emphasized data theft and extortion rather than conventional ransomware encryption, although later reporting also described experimentation with broader extortion and access-sale models and claimed collaboration or alignment with other criminal ecosystems. Observed tradecraft includes phishing for information, spearphishing by voice, credential theft, exploitation of authentication systems, privilege escalation, and post-compromise data exfiltration. LAPSUS$ has also publicly recruited for vishing operations and has been linked to theft and sale of access or stolen datasets. Reporting in 2025 and 2026 described an SLH alliance involving LAPSUS$, Scattered Spider, and ShinyHunters, followed by claims of retirement and later return under an extortion-oriented model. In July 2026, LAPSUS$ publicly claimed it was permanently shutting down after achieving its financial goals, but some contemporaneous claims around collaboration with TeamPCP and specific victim incidents remained unverified. Individuals publicly linked to LAPSUS$ include Arion Kurtaj and Thalha Jubair in UK proceedings related to major intrusions. The actor’s history illustrates the growing role of socially engineered access, identity compromise, and rapid monetization of stolen corporate data in modern cybercrime.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
18 malware families attributed to this actor across reporting.
13 additional families tracked in Mallory.
10 CVEs this actor has used in observed campaigns. 10 of them exploited in the wild.
BleepingComputer reported that threat actors leveraged credentials stolen through the Trivy supply chain compromise (CVE-2026-33634) to breach Cisco's internal development environment... The CISA KEV remediation deadline for CVE-2026-33634 is today, April 8, 2026... Beyond patching Trivy to v0.69.2+, trivy-action to v0.35.0, or setup-trivy to v0.2.6, organizations must also complete credential rotation for any secrets that may have been exposed during the March 19-27 compromise window.
The CVE-2025-61882 campaign is particularly instructive. CrowdStrike assessed with moderate confidence that GRACEFUL SPIDER was involved in mass exploitation of that vulnerability... Exploitation had begun nearly two months earlier on August 9, 2025, well before Oracle's public disclosure.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
5 more CVEs tied to this actor tracked in Mallory.
16 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a reported criminal link in connection with publication of European Commission data associated with TeamPCP activity.
Announces a permanent shutdown of operations, claims it achieved its financial goals, says it will cease communications, data leaks, and access sales, and alleges it sold Mercor user data to Chinese entities. The group is also described as having formed the SLH alliance, returned with an Extortion-as-a-Service model, and recruited women for vishing campaigns.
Named in the breach sale post as the group name allegedly associated with the Mercor compromise, but the attribution is explicitly unconfirmed and the name may have been reused by others.
Referenced as an example of Microsoft's weather-based naming convention, where Tempest denotes financially motivated cybercriminal groups not tied to a nation-state.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.