Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G1004
MITRE ATT&CK Group

LAPSUS$ (G1004)

DEV-0537Strawberry Tempest
ShareXLinkedInRedditHN

[LAPSUS$](https://attack.mitre.org/groups/G1004) is cyber criminal threat group that has been active since at least mid-2021. [LAPSUS$](https://attack.mitre.org/groups/G1004) specializes in large-scale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.(Citation: BBC LAPSUS Apr 2022)(Citation: MSTIC DEV-0537 Mar 2022)(Citation: UNIT 42 LAPSUS Mar 2022)

▪Techniques used (44)

T1589Gather Victim Identity InformationT1005Data from Local SystemT1069.002Domain GroupsT1213.001ConfluenceT1588.002ToolT1485Data DestructionT1213.003Code RepositoriesT1213.002SharepointT1583.003Virtual Private ServerT1591.004Identify RolesT1090ProxyT1087.002Domain AccountT1133External Remote ServicesT1078Valid AccountsT1588.001MalwareT1598.004Spearphishing VoiceT1204User ExecutionT1552.008Chat MessagesT1489Service StopT1593.003Code RepositoriesT1136.003Cloud AccountT1114.003Email Forwarding RuleT1591.002Business RelationshipsT1578.003Delete Cloud InstanceT1555.003Credentials from Web BrowsersT1531Account Access RemovalT1589.001CredentialsT1068Exploitation for Privilege EscalationT1621Multi-Factor Authentication Request GenerationT1098.003Additional Cloud RolesT1003.006DCSyncT1586.002Email AccountsT1213.005Messaging ApplicationsT1589.002Email AddressesT1584.002DNS ServerT1684.001ImpersonationT1003.003NTDST1555.005Password ManagersT1199Trusted RelationshipT1597.002Purchase Technical DataT1578.002Create Cloud InstanceT1078.004Cloud AccountsT1111Multi-Factor Authentication InterceptionT1451SIM Card Swap

▪Software used (1)

S0002Mimikatztool
G1004on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.