Lapsus Group

Threat Actor updated 7 months ago (2024-05-04T20:55:40.635Z)
Download STIX
Preview STIX
The Lapsus Group, identified as a threat actor originating from North Korea, has been involved in various cybercriminal activities, primarily focusing on cryptocurrency theft. This group is known for its use of sophisticated tools such as RedLine and QakBot, which have been instrumental in their operations. According to cybersecurity firm ReliaQuest, the Lapsus Group's activities are persistent and show signs of resurgence. In one notable incident, an employee was subjected to "MFA fatigue" by a hacker from the Lapsus Group, who sent multiple multi-factor authentication notifications to the victim's device. This tactic is indicative of the group's advanced strategies to compromise security measures. Furthermore, the Lapsus Group has shown resilience and adaptability; despite being disbanded in 2022, it managed to revive itself and continue its malicious activities. The threat posed by the Lapsus Group extends to large corporations as well. In the summer of 2022, the group successfully breached a trillion-dollar company using just one compromised credential, demonstrating their ability to infiltrate high-value targets. This event underscores the group's capability to exploit even minor security vulnerabilities to gain access to sensitive information, including source code. The naming conventions for such groups vary across different cybersecurity entities; for instance, CrowdStrike refers to this group as "Scattered Spider," while another name used is SLIPPY SPIDER.
Description last updated: 2024-05-04T17:37:51.375Z
What's your take? (Question 1 of 1)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Malware
To see the evidence that has resulted in these malware associations, create a free account
Alias DescriptionAssociation TypeVotes
The Redline Malware is associated with Lapsus Group. RedLine is a type of malware, a malicious software designed to exploit and damage computer systems. It often infiltrates systems through suspicious downloads, emails, or websites and can steal personal information, disrupt operations, or hold data for ransom. RedLine has been favored by threat actorUnspecified
2
The QakBot Malware is associated with Lapsus Group. Qakbot is a malicious software (malware) designed to exploit and damage computer systems. It infiltrates systems through suspicious downloads, emails, or websites, often unbeknownst to the user, with the potential to steal personal information, disrupt operations, or hold data for ransom. Built by dUnspecified
2
Source Document References
Information about the Lapsus Group Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more