Ransomware Group intelligence
Lapsus$
ActiveTrack Lapsus$ with 28 published victims and 5 known leak locations in a single intelligence view.
Overview
Lapsus$ is tracked by Breach House as a ransomware group with 28 published victims.
United States is currently the most targeted country in this dataset.
5 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (5)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 4 | Web location | Up checked 1h ago | lapsus.bz |
| Leak location 3 | Onion service | Down checked 1h ago | mwojud552brg7rl3obqjvv2funhwpg6acdsuuoeytq7365kmaeoi4gqd.onion |
| File host (third party) | Third-party file host | Down checked 1h ago | anonfilesnew.com |
| Leak location 1 | Web location | Down checked 1h ago | lapsus.cz |
| Leak location 2 | Web location | Down checked 1h ago | lapsus.by |
Top Activity Sectors (11)
Typical Attacks (43)
▼How Lapsus$ typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via LAPSUS$.
-
T1589 Gather Victim Identity Information Reconnaissance
What they do: LAPSUS$ has gathered detailed information of target employees to enhance their social engineering lures.
What that means: Adversaries may gather information about the victim's identity that can be used during targeting.
-
T1589.001 Credentials Reconnaissance
What they do: LAPSUS$ has gathered user identities and credentials to gain initial access to a victim's organization; the group has also called an organization's help desk to reset a target's credentials.
What that means: Adversaries may gather credentials that can be used during targeting.
-
T1589.002 Email Addresses Reconnaissance
What they do: LAPSUS$ has gathered employee email addresses, including personal accounts, for social engineering and initial access efforts.
What that means: Adversaries may gather email addresses that can be used during targeting.
-
T1591.002 Business Relationships Reconnaissance
What they do: LAPSUS$ has gathered detailed knowledge of an organization's supply chain relationships.
What that means: Adversaries may gather information about the victim's business relationships that can be used during targeting.
-
T1591.004 Identify Roles Reconnaissance
What they do: LAPSUS$ has gathered detailed knowledge of team structures within a target organization.
What that means: Adversaries may gather information about identities and roles within the victim organization that can be used during targeting.
-
T1593.003 Code Repositories Reconnaissance
What they do: LAPSUS$ has searched public code repositories for exposed credentials.
What that means: Adversaries may search public code repositories for information about victims that can be used during targeting.
-
T1597.002 Purchase Technical Data Reconnaissance
What they do: LAPSUS$ has purchased credentials and session tokens from criminal underground forums.
What that means: Adversaries may purchase technical information about victims that can be used during targeting.
-
T1598.004 Spearphishing Voice Reconnaissance
What they do: LAPSUS$ has called victims' help desk to convince the support personnel to reset a privileged account’s credentials.
What that means: Adversaries may use voice communications to elicit sensitive information that can be used during targeting.
-
T1583.003 Virtual Private Server Resource Development
What they do: LAPSUS$ has used VPS hosting providers for infrastructure.
What that means: Adversaries may rent Virtual Private Servers (VPSs) that can be used during targeting.
-
T1584.002 DNS Server Resource Development
What they do: LAPSUS$ has reconfigured a victim's DNS records to actor-controlled domains and websites.
What that means: Adversaries may compromise third-party DNS servers that can be used during targeting.
-
T1586.002 Email Accounts Resource Development
What they do: LAPSUS$ has payed employees, suppliers, and business partners of target organizations for credentials.
What that means: Adversaries may compromise email accounts that can be used during targeting.
-
T1588.001 Malware Resource Development
What they do: LAPSUS$ acquired and used the Redline password stealer in their operations.
What that means: Adversaries may buy, steal, or download malware that can be used during targeting.
-
T1588.002 Tool Resource Development
What they do: LAPSUS$ has obtained tools such as RVTools and AD Explorer for their operations.
What that means: Adversaries may buy, steal, or download software tools that can be used during targeting.
-
What they do: LAPSUS$ has used compromised credentials and/or session tokens to gain access into a victim's VPN, VDI, RDP, and IAMs.
What that means: Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
What they do: LAPSUS$ has used compromised credentials to access cloud assets within a target organization.
What that means: Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
What they do: LAPSUS$ has gained access to internet-facing systems and applications, including virtual private network (VPN), remote desktop protocol (RDP), and virtual desktop infrastructure (VDI) including Citrix.
What that means: Adversaries may leverage external-facing remote services to initially access and/or persist within a network.
-
T1199 Trusted Relationship Initial Access
What they do: LAPSUS$ has accessed internet-facing identity providers such as Azure Active Directory and Okta to target specific organizations.
What that means: Adversaries may breach or otherwise leverage organizations who have access to intended victims.
-
T1204 User Execution Execution
What they do: LAPSUS$ has recruited target organization employees or contractors who provide credentials and approve an associated MFA prompt, or install remote management software onto a corporate workstation, allowing LAPSUS$ to take control of an authenticated system.
What that means: An adversary may rely upon specific actions by a user in order to gain execution.
-
What they do: LAPSUS$ has added the global admin role to accounts they have created in the targeted organization's cloud instances.
What that means: An adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant.
-
T1136.003 Cloud Account Persistence
What they do: LAPSUS$ has created global admin accounts in the targeted organization's cloud instances to gain persistence.
What that means: Adversaries may create a cloud account to maintain access to victim systems.
-
T1068 Exploitation for Privilege Escalation Privilege Escalation
What they do: LAPSUS$ has exploited unpatched vulnerabilities on internally accessible servers including JIRA, GitLab, and Confluence for privilege escalation.
What that means: Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
-
T1684.001 Impersonation Stealth
What they do: LAPSUS$ has called victims' help desk and impersonated legitimate users with previously gathered information in order to gain access to privileged accounts.
What that means: Adversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf.
-
T1578.002 Create Cloud Instance Defense Impairment
What they do: LAPSUS$ has created new virtual machines within the target's cloud environment after leveraging credential access to cloud assets.
What that means: An adversary may create a new instance or virtual machine (VM) within the compute service of a cloud account to evade defenses.
-
T1578.003 Delete Cloud Instance Defense Impairment
What they do: LAPSUS$ has deleted the target's systems and resources in the cloud to trigger the organization's incident and crisis response process.
What that means: An adversary may delete a cloud instance after they have performed malicious activities in an attempt to evade detection and remove evidence of their presence.
-
T1003.003 NTDS Credential Access
What they do: LAPSUS$ has used Windows built-in tool `ntdsutil` to extract the Active Directory (AD) database.
What that means: Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights.
-
T1003.006 DCSync Credential Access
What they do: LAPSUS$ has used DCSync attacks to gather credentials for privilege escalation routines.
What that means: Adversaries may attempt to access credentials and other sensitive information by abusing a Windows Domain Controller's application programming interface (API) to simulate the replication process from a remote domain controller using a technique called DCSync.
-
T1111 Multi-Factor Authentication Interception Credential Access
What they do: LAPSUS$ has replayed stolen session token and passwords to trigger simple-approval MFA prompts in hope of the legitimate user will grant necessary approval.
What that means: Adversaries may target multi-factor authentication (MFA) mechanisms, (i.e., smart cards, token generators, etc.) to gain access to credentials that can be used to access systems, services, and network resources.
-
T1552.008 Chat Messages Credential Access
What they do: LAPSUS$ has targeted various collaboration tools like Slack, Teams, JIRA, Confluence, and others to hunt for exposed credentials to support privilege escalation and lateral movement.
What that means: Adversaries may directly collect unsecured credentials stored or passed through user communication services.
-
T1555.003 Credentials from Web Browsers Credential Access
What they do: LAPSUS$ has obtained passwords and session tokens with the use of the Redline password stealer.
What that means: Adversaries may acquire credentials from web browsers by reading files specific to the target browser.
-
T1555.005 Password Managers Credential Access
What they do: LAPSUS$ has accessed local password managers and databases to obtain further credentials from a compromised network.
What that means: Adversaries may acquire user credentials from third-party password managers.
-
T1621 Multi-Factor Authentication Request Generation Credential Access
What they do: LAPSUS$ has spammed target users with MFA prompts in the hope that the legitimate user will grant necessary approval.
What that means: Adversaries may attempt to bypass multi-factor authentication (MFA) mechanisms and gain access to accounts by generating MFA requests sent to users.
-
T1069.002 Domain Groups Discovery
What they do: LAPSUS$ has used the AD Explorer tool to enumerate groups on a victim's network.
What that means: Adversaries may attempt to find domain-level groups and permission settings.
-
T1087.002 Domain Account Discovery
What they do: LAPSUS$ has used the AD Explorer tool to enumerate users on a victim's network.
What that means: Adversaries may attempt to get a listing of domain accounts.
-
T1005 Data from Local System Collection
What they do: LAPSUS$ uploaded sensitive files, information, and credentials from a targeted organization for extortion or public release.
What that means: Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.
-
T1114.003 Email Forwarding Rule Collection
What they do: LAPSUS$ has set an Office 365 tenant level mail transport rule to send all mail in and out of the targeted organization to the newly created account.
What that means: Adversaries may setup email forwarding rules to collect sensitive information.
-
T1213.001 Confluence Collection
What they do: LAPSUS$ has searched a victim's network for collaboration platforms like Confluence and JIRA to discover further high-privilege account credentials.
What that means: Adversaries may leverage Confluence repositories to mine valuable information.
-
T1213.002 Sharepoint Collection
What they do: LAPSUS$ has searched a victim's network for collaboration platforms like SharePoint to discover further high-privilege account credentials.
What that means: Adversaries may leverage the SharePoint repository as a source to mine valuable information.
-
T1213.003 Code Repositories Collection
What they do: LAPSUS$ has searched a victim's network for code repositories like GitLab and GitHub to discover further high-privilege account credentials.
What that means: Adversaries may leverage code repositories to collect valuable information.
-
T1213.005 Messaging Applications Collection
What they do: LAPSUS$ has searched a victim's network for organization collaboration channels like MS Teams or Slack to discover further high-privilege account credentials.
What that means: Adversaries may leverage chat and messaging applications, such as Microsoft Teams, Google Chat, and Slack, to mine valuable information.
-
T1090 Proxy Command and Control
What they do: LAPSUS$ has leverage NordVPN for its egress points when targeting intended victims.
What that means: Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure.
-
T1485 Data Destruction Impact
What they do: LAPSUS$ has deleted the target's systems and resources both on-premises and in the cloud.
What that means: Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources.
-
T1489 Service Stop Impact
What they do: LAPSUS$ has shut down virtual machines from within a victim's on-premise VMware ESXi infrastructure.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1531 Account Access Removal Impact
What they do: LAPSUS$ has removed a targeted organization's global admin accounts to lock the organization out of all access.
What that means: Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users.
Tools Observed (4)
▼Software Lapsus$ has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Discovery & enumeration
LOLBAS (living-off-the-land binaries)
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Victims (28)
Search, filter and paginate the victim timeline for Lapsus$. Showing 1–28 of 28.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | AYA BANK id29995 View details | Myanmar | Finance / Legal / Insurance | — | |
|
AYA Bank is a major bank in Myanmar, operating in the finance sector and providing a range of banking services to individuals and businesses. As a key player in the country's financial industry, AYA Bank offers various products and services, including deposit accounts, loans, and credit cards. AYA Bank was listed as a ransomware victim associated with lapsus$ |
|||||
| Ransomware | AYA BANK id29995 View details | Myanmar | Finance / Legal / Insurance | — | |
|
Everything for the main platform is there. Full dump and PII data's. If AYA Bank dont contact us or pay the ransom we will start sale |
|||||
| Ransomware | INGKA GROUP id29853 View details | Sweden | Retail / E-commerce | ||
|
Full mapping of global e-commerce architecture and internal coworker platforms. Supply chain logistics, cloud infrastructure, and AI/MLOps repositories |
|||||
| Ransomware | GITHUB INTERNAL id29854 View details | United States | IT | — | |
|
Everything for the main platform is there. No ransom, we do not care about extorting Github. If no buyer is found, we leak for free. |
|||||
| Ransomware | MERCOR id29533 View details | Other | — | ||
|
This data has been acquired by a private party. No public leak will occur. |
|||||
| Ransomware | MAPFRE ASSURANCE id29534 View details | Spain | Finance / Legal / Insurance | — | |
|
This data has been acquired by a private party. No public leak will occur. |
|||||
| Ransomware | VODAFONE id29390 View details | Germany | Other | — | |
|
Full Infrastructure, Source Code, GitHub Tree & Internal Network Maps |
|||||
| Ransomware | AXCERA TRADING id29040 View details | United States | Other | — | |
|
Trading Algorithms, Client Portfolios, KYC Data & Financial Logs |
|||||
| Ransomware | CHECKMARX id28624 View details | United States | IT | — | |
|
Source Code, Employee DB, API Keys, MongoDB/MySQL Creds |
|||||
| Ransomware | AXCERA.IO id27915 View details | United States | IT | — | |
|
Source Code + Infrastructure Configs |
|||||
| Ransomware | FR MINISTRY AGRICULTURE id27914 View details | France | Public Sector | — | |
|
FR Ministry Agriculture refers to France’s national Ministry of Agriculture and Food Sovereignty, the government body responsible for agriculture, agri-food, forestry, wood industry, fisheries, and aquaculture policy. It is based in Paris and operates as part of the French public sector, coordinating state policy across the country’s food and agricultural systems. In threat-intelligence contexts, the name identifies a government institution rather than a commercial supplier or private brand. FR Ministry Agriculture was listed as a ransomware victim associated with lapsus$. |
|||||
| Ransomware | UNIV LILLE id27913 View details | France | Education | — | |
|
UNIV LILLE refers to the University of Lille, a public university in Lille, France, in the education sector. The institution brings together multiple academic units, including faculties, institutes, internal schools, and grandes écoles, and serves students across a broad range of disciplines. It is a state university with a public research profile and a multi-campus structure in northern France. In threat-intelligence listings, UNIV LILLE was identified as a ransomware victim associated with lapsus$. |
|||||
| Ransomware | ASTRAZENECA CORP id27912 View details | United Kingdom | Healthcare / Pharma | — | |
|
Source Code, Employee DB, API Keys, MongoDB/MySQL Creds |
|||||
| Ransomware | VirtaHealth id27911 View details | United States | Healthcare / Pharma | — | |
|
Healthcare research |
|||||
| Ransomware | Eiffage id26946 View details | France | Construction / Real Estate | — | |
|
[AI generated] Eiffage S.A. is a French publicly-listed company established in 1993, specializing in civil engineering and construction. Its activities are divided into five main segments: Construction, Infrastructure, Real Estate Development, Metal, and Concessions & Energy. It is known for working on significant projects such as the Eiffel Tower and the Millau Viaduct. Eiffage operates not only in France but also in more than 50 countries worldwide. |
|||||
| Ransomware | OSAC Aero id26945 View details | France | Communication / Marketing | — | |
|
[AI generated] "OSAC Aero" is a Spanish aeronautical engineering company. They provide aeronautical consulting services, product development, aircraft maintenance, and also focus on designing, prototyping, and manufacturing aerostructures. Their innovative solutions have established OSAC as a reliable partner for leading global aerospace organizations. |
|||||
| Ransomware | Salesfloor id26944 View details | Canada | Retail / E-commerce | — | |
|
[AI generated] Salesfloor is a software company that provides a mobile platform designed to connect retail store associates with online shoppers for a personalized customer experience. It empowers store associates to create and maintain personalized relationships through social selling, online engagement and clienteling tactics. Its services are used by leading retailers around the world. |
|||||
| Ransomware | Adidas id26943 View details | Germany | Education | — | |
|
[AI generated] Adidas is a renowned German multinational corporation that specializes in sports apparel, shoes, and accessories. Founded by Adolf Dassler in 1949, its headquarters located in Herzogenaurach, Germany. The company is globally recognized for its performance and lifestyle products, including football kits, running shoes, training gear and streetwear. Today, Adidas stands as one of the leading sports brands worldwide. |
|||||
| Ransomware | Loozap id26942 View details | Switzerland | Communication / Marketing | — | |
|
[AI generated] Loozap is an online marketplace that provides a platform for users to buy and sell second-hand items. They operate in multiple countries across Africa, including Ghana and Kenya. Their inventory includes items such as cars, homes, electronics, furniture, and clothing. The platform adopts an innovative system that enhances the buying and selling experience. |
|||||
| Ransomware | Lacoste id26941 View details | France | Retail / E-commerce | — | |
|
[AI generated] Lacoste is a high-end French clothing company founded in 1933 by tennis player René Lacoste and André Gillier. The company is renowned for its iconic green crocodile logo. They primarily produce clothing, footwear, sportswear, eyewear, leather goods, and perfumes. Its polo shirts are particularly popular. Lacoste products are sold internationally at various department stores, shopping malls, and standalone boutiques. |
|||||
| Ransomware | DreamUp id26940 View details | United States | Communication / Marketing | — | |
|
[AI generated] DreamUp is an American company that provides space-based educational opportunities to students of all ages. They offer various programs that utilize the unique environment of space to spark interest in Science, Technology, Engineering, and Mathematics (STEM) fields. DreamUp provides tools to conduct research in microgravity through partnerships with SpaceX, the International Space Station and other space organizations. |
|||||
| Ransomware | Lille University id26939 View details | France | Education | — | |
|
[AI generated] Lille University, also known as University of Lille, is a well-recognized public university located in Lille, France. It was established in 1562 and offers a wide range of educational programs covering multiple disciplines. The university is known for its focus on research and innovation, and boasts a diverse student population from around the globe. In addition to its academic achievements, Lille University also encourages sports and cultural activities. |
|||||
| Ransomware | FR Ministry of Agriculture id26938 View details | France | Agriculture / Food | — | |
|
[AI generated] The FR Ministry of Agriculture, or the French Ministry of Agriculture, is a governmental body in France overseeing agriculture, forestry, and food processing. It develops policies to support farming and rural development, ensures food quality and safety, and handles fisheries and animal welfare. The ministry also plays crucial roles in research, education, and regulation of agricultural and food markets in France. |
|||||
| Ransomware | Eni Energy id26937 View details | Italy | Energy | — | |
|
[AI generated] Eni Energy is an Italian multinational oil and gas company headquartered in Rome. Founded in 1953, the firm is considered one of the global supermajors in the oil industry. It operates in 66 countries worldwide, and its activities span oil and gas exploration, production, and refining, as well as electricity and chemical production. Environmental sustainability is a critical focus area, with significant investments into renewable energy sources. |
|||||
| Ransomware | Samsung Electronics id2778 View details | Japan | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Nvidia id2693 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Impresa id2335 View details | Portugal | Communication / Marketing | — | |
|
No additional victim description available. |
|||||
| Ransomware | Brazilian Ministry of Health id2154 View details | Brazil | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||