news.mlab.sh
Back to the feed
threat-intel

LAPSUS$ réapparaît autour d’une attaque contre Courir

High
Summary

The LAPSUS$ group, a notorious name in cybercrime, has seemingly resurfaced, attempting to rebuild its operations and recruit insiders. The group, claiming continuity with its past, is now seeking privileged access within telecom, SaaS, cloud, and hosting environments, offering exclusive access packages. Following this recruitment drive, the group claimed to have compromised Courir, seeking to establish a persistent presence and monetize access to sensitive data. This signals a broader effort to reestablish LAPSUS$ as a recruitment and access-selling platform within the cybercrime ecosystem, rather than a specific, continuous operation.

The LAPSUS$ group, a name synonymous with disruptive attacks and data breaches in the past, has reportedly attempted to re-emerge within the cybercrime landscape. According to a recent post on a dark web forum, an account claiming to be an ‘Old Official Account’ linked to LAPSUS$ is actively seeking to rebuild its operations and recruit individuals with privileged access to various industries. The group is now explicitly looking for insiders and collaborators possessing access to environments within the telecommunications, SaaS, cloud computing, and hosting sectors.

This recruitment drive is accompanied by a promise of exclusive ‘packages’ of access, with a session identifier mirroring those used in the recruitment campaign, suggesting a monetization strategy. The account claims to be operating under the banner of SLSH, a coalition including Scattered Spider, LAPSUS$, and ShinyHunters. It further asserts that several members have been arrested and promises to release a substantial volume of data, documents, and sensitive information in the near future.

Adding to the intrigue, the account claims to have compromised Courir over several weeks, maintaining a persistent presence across multiple infrastructure segments, including administrative control of development portals and privileged service accounts, enabling lateral movement. The attacker claims to have mapped, compromised, and exfiltrated assets from both production and development environments.

However, the evidence presented – screenshots purportedly demonstrating access – is not conclusive and does not definitively prove the extent of the Courir compromise. The post also highlights a clear commercial motive, with the account offering exclusive access packages to potential buyers.

Notably, the ShinyHunters group, a known associate of LAPSUS$, has not acknowledged this coalition. This resurgence isn't necessarily about a continuous operation of LAPSUS$ as it once was, but rather a deliberate attempt to leverage the group's established reputation and network to acquire privileged access and monetize it within the cybercrime ecosystem. For ZATAZ, the key takeaway is the strategic shift – LAPSUS$ is being repurposed as a recruitment and access-selling platform, rather than a continuous threat actor.

Read the full article at ZATAZ