LAPSUS__2022__nccgroup_LAPSUS-Recent-TTPs_04-28-2022.pdf
ID: a5514440-e3cd-4dee-8d77-492eaa86d3c0
STIX ID: report--a5514440-e3cd-4dee-8d77-492eaa86d3c0
Threat Score
72/100
Uploaded: 2026-08-15
Published Date: 2022-04-29
Last Modified Date: 2022-04-29
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**NCC Group analysis of LAPSUS$ TTPs:** The report summarizes observed LAPSUS$ activity — initial access via stolen SSO cookies and social engineering/insider recruitment, rapid credential harvesting and privilege escalation, lateral movement via RDP and VPN, targeted exfiltration of source code and API keys (often using public file drop services), and disruptive/destructive actions against virtual infrastructure; it provides mitigation recommendations, MITRE ATT&CK mappings and several IOCs.
