news.mlab.sh
Threat intelligence
Threat actor

Lapsus$

Profile from actors.mlab.sh, coverage from our own index.

Suspected origin
Brazil
Targeted countries
Brazil
TLP
WHITE

(Flashpoint) LAPSUS$ is an extortionist threat group that became active on December 10, 2921. Unlike the majority of extortionist groups that typically rely on a combination of ransomware and data leaks, LAPSUS$ is focused on monetizing their operations exclusively through data leaks advertised on Telegram without the use of ransomware. Initially, the group focused on data breaches against Latin American and Portuguese targets but in late February 2022, LAPSUS$ began widening the scope of its targeting by announcing it had successfully breached US-based graphics and computing chip manufacturer Nvidia. Since then, LAPSUS$ has continued to focus on large-scale international technology companies, including Microsoft, Okta, and Samsung, as the financial incentive for stealing source code and extorting companies for sensitive proprietary technical data is high. Around July 2025, ShinyHunters teamed up or merged with Subgroup: Scattered Spider. They share their Telegram channel also with Lapsus$, so they may all work together now – see the DataBreaches.net references in the Information section under ShinyHunters.

Also known as

DEV-0537G1004LAPSUS$Slippy SpiderStrawberry Tempest

Tooling and malware

Mimikatz

MITRE ATT&CK techniques

T1005 Data from Local SystemT1090 ProxyT1111 Multi-Factor Authentication InterceptionT1621 Multi-Factor Authentication Request GenerationT1204 User ExecutionT1485 Data DestructionT1489 Service StopT1531 Account Access RemovalT1199 Trusted RelationshipT1133 External Remote ServicesT1068 Exploitation for Privilege EscalationT1589 Gather Victim Identity InformationT1078 Valid Accounts

Coverage 6