LAPSUS$ is a financially motivated and notoriety-seeking cybercriminal extortion group tracked by Microsoft as DEV-0537 and Strawberry Tempest, and also known as Slippy Spider. Active since at least 2021, it is distinguished by high-profile social-engineering intrusions, theft and public release of sensitive data and source code, and occasional destructive activity rather than conventional ransomware deployment. The group has conducted pure data-extortion operations, typically without encrypting victim systems. LAPSUS$ primarily obtains access through identity compromise: purchasing stolen credentials and session tokens, using commodity infostealers including RedLine, replaying browser sessions, MFA fatigue, SIM swapping, vishing, help-desk manipulation, and recruiting employees, suppliers, or partners to provide credentials or approve MFA requests. It has also searched public code repositories for exposed secrets and exploited unpatched internally reachable services. Following access, the group enumerates directory environments and collaboration platforms, searches enterprise repositories and messaging systems for secrets and privileged access paths, performs credential theft and privilege escalation, and exfiltrates sensitive data for extortion or public disclosure. It has used Active Directory replication abuse and credential-dumping tooling after obtaining elevated access. The actor has targeted organizations globally, including government, technology, telecommunications, media, retail, health care, manufacturing, energy, and higher-education entities. Publicly linked victims include Brazilian government and telecommunications organizations, a Portuguese media company, and major technology, gaming, identity, telecommunications, and financial-services companies. LAPSUS$ has also targeted cryptocurrency-exchange users for cryptocurrency theft. In some intrusions, it deleted cloud and on-premises resources, created or abused privileged cloud accounts, altered email-routing controls, and interfered with victims' incident-response communications to monitor and pressure targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
55 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 malware families attributed to this actor across reporting.
15 additional families tracked in Mallory.
28 CVEs this actor has used in observed campaigns. 28 of them exploited in the wild.
BleepingComputer reported that threat actors leveraged credentials stolen through the Trivy supply chain compromise (CVE-2026-33634) to breach Cisco's internal development environment... The CISA KEV remediation deadline for CVE-2026-33634 is today, April 8, 2026... Beyond patching Trivy to v0.69.2+, trivy-action to v0.35.0, or setup-trivy to v0.2.6, organizations must also complete credential rotation for any secrets that may have been exposed during the March 19-27 compromise window.
The CVE-2025-61882 campaign is particularly instructive. CrowdStrike assessed with moderate confidence that GRACEFUL SPIDER was involved in mass exploitation of that vulnerability... Exploitation had begun nearly two months earlier on August 9, 2025, well before Oracle's public disclosure.
CVEs targeted by Lapsus$ CVE-2021-31207: Microsoft Exchange Server Security Feature Bypass Vulnerability
CVEs targeted by Lapsus$ CVE-2021-34473: Microsoft Exchange Server Remote Code Execution Vulnerability
CVEs targeted by Lapsus$ CVE-2018-13379: An Improper Limitation of a Pathname to a Restricted Directory (“Path Traversal”) in Fortinet
23 more CVEs tied to this actor tracked in Mallory.
39 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned solely as historical context for the separate September 2022 Rockstar breach; explicitly stated to be unrelated to Cyberleek.
Referenced as the group associated with Rockstar's separate 2022 security incident, in which leaked gameplay footage caused significant losses.
Listed in the detection's APT annotations.
LAPSUS$ is listed in the detection's ATT&CK annotations for T1068, Exploitation for Privilege Escalation.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.