logo

LAPSUS__2022__nccgroup_LAPSUS-Recent-TTPs_04-28-2022.pdf

ID: a5514440-e3cd-4dee-8d77-492eaa86d3c0

STIX ID: report--a5514440-e3cd-4dee-8d77-492eaa86d3c0

Threat Score

72/100

Uploaded: 2026-08-15

Published Date: 2022-04-29

Last Modified Date: 2022-04-29

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**NCC Group analysis of LAPSUS$ TTPs:** The report summarizes observed LAPSUS$ activity — initial access via stolen SSO cookies and social engineering/insider recruitment, rapid credential harvesting and privilege escalation, lateral movement via RDP and VPN, targeted exfiltration of source code and API keys (often using public file drop services), and disruptive/destructive actions against virtual infrastructure; it provides mitigation recommendations, MITRE ATT&CK mappings and several IOCs.