LAPSUS$ is a financially motivated extortion and intrusion group best known for high-profile compromises of major technology, telecommunications, gaming, and identity-management organizations. The group is widely tracked under aliases including DEV-0537, Slippy Spider, and Strawberry Tempest. Public reporting and law-enforcement actions have linked parts of the group to young, primarily English-speaking operators, including individuals in the United Kingdom, rather than to a nation-state apparatus. LAPSUS$ became notable for aggressive social engineering, rapid smash-and-grab intrusions, public victim shaming, and data-theft extortion. The group has been associated with compromises affecting organizations such as Microsoft, Samsung, Nvidia, Ubisoft, Okta, Globant, and Rockstar Games, and later victim claims have also included additional enterprises in finance, retail, and telecommunications. Some more recent victim claims remain unconfirmed and should be treated cautiously. Operationally, LAPSUS$ has been associated less with bespoke stealth malware than with human-centric intrusion tradecraft. Reported techniques include social engineering of help desks and employees, credential theft and reuse, insider recruitment or bribery, abuse of remote access and identity systems, and exploitation of authentication workflows to obtain privileged access. The group has also been linked to extortion activity involving stolen source code, internal communications, customer data, and other sensitive corporate information. In some incidents, LAPSUS$ publicly advertised stolen data, released samples to pressure victims, or offered access and datasets for sale. The group has shown overlap or interaction with broader cybercriminal ecosystems, including communities associated with The Com and, in some reporting, collaboration or parallel activity involving actors such as TeamPCP, ShinyHunters, and Scattered Spider. These relationships appear opportunistic and criminal rather than indicative of formal centralized command. Reporting has also noted possible reuse of former LAPSUS$ tooling or community infrastructure by adjacent actors. Law-enforcement and court proceedings have tied named individuals associated with LAPSUS$ to intrusions against Nvidia, BT/EE, and Rockstar Games, among others. Arion Kurtaj has been publicly linked to the group in connection with the 2022 Rockstar Games intrusion and GTA 6 leak. Separate UK proceedings have also linked Thalha Jubair to LAPSUS$ in addition to Scattered Spider and The Com. These cases reinforced the assessment that LAPSUS$ functioned as a loose, youth-driven cybercriminal collective centered on social engineering, credential abuse, and extortion rather than a traditional malware-heavy ransomware operation. Overall, LAPSUS$ is best characterized as a high-impact cybercriminal threat actor specializing in socially engineered initial access, theft of sensitive enterprise data, and coercive public extortion against prominent organizations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
18 malware families attributed to this actor across reporting.
13 additional families tracked in Mallory.
10 CVEs this actor has used in observed campaigns. 10 of them exploited in the wild.
threat actors leveraged credentials stolen through the Trivy supply chain compromise (CVE-2026-33634) to breach Cisco's internal development environment... The CISA KEV remediation deadline for CVE-2026-33634 is today, April 8, 2026... Beyond patching Trivy to v0.69.2+, trivy-action to v0.35.0, or setup-trivy to v0.2.6, organizations must also complete credential rotation
The CVE-2025-61882 campaign is particularly instructive. CrowdStrike assessed with moderate confidence that GRACEFUL SPIDER was involved in mass exploitation of that vulnerability... Exploitation had begun nearly two months earlier on August 9, 2025, well before Oracle's public disclosure.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
5 more CVEs tied to this actor tracked in Mallory.
16 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as another cybercriminal group to which one of the convicted individuals was linked; not the primary actor discussed for the TfL incident.
A financially motivated hacking group linked here to the 2022 GTA 6 leak and other intrusions against major technology and gaming companies. The content says its methods included social engineering, insider bribery, and exploiting authentication systems.
Mentioned as Jubair's prior cybercrime affiliation in an earlier case, not as the primary subject of this article.
Named as a ransomware/data extortion threat actor posting a financial-sector victim and advertising a large stolen data dump.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.