Brown, D., et al. (2022, April 28). LAPSUS$: Recent techniques, tactics and procedures. Retrieved December 22, 2022.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1078 Valid Accounts |
GroupLAPSUS$ | LAPSUS$ has used compromised credentials and/or session tokens to gain access into a victim's VPN, VDI, RDP, and IAMs. |
| T1087.002 Domain Account |
GroupLAPSUS$ | LAPSUS$ has used the AD Explorer tool to enumerate users on a victim's network. |
| T1133 External Remote Services |
GroupLAPSUS$ | LAPSUS$ has gained access to internet-facing systems and applications, including virtual private network (VPN), remote desktop protocol (RDP), and virtual desktop infrastructure (VDI) including Citrix. |
| T1213.002 Sharepoint |
GroupLAPSUS$ | LAPSUS$ has searched a victim's network for collaboration platforms like SharePoint to discover further high-privilege account credentials. |
| T1213.003 Code Repositories |
GroupLAPSUS$ | LAPSUS$ has searched a victim's network for code repositories like GitLab and GitHub to discover further high-privilege account credentials. |
| T1485 Data Destruction |
GroupLAPSUS$ | LAPSUS$ has deleted the target's systems and resources both on-premises and in the cloud. |
| T1489 Service Stop |
GroupLAPSUS$ | LAPSUS$ has shut down virtual machines from within a victim's on-premise VMware ESXi infrastructure. |
| T1555.005 Password Managers |
GroupLAPSUS$ | LAPSUS$ has accessed local password managers and databases to obtain further credentials from a compromised network. |
| T1584.002 DNS Server |
GroupLAPSUS$ | LAPSUS$ has reconfigured a victim's DNS records to actor-controlled domains and websites. |
| T1586.002 Email Accounts |
GroupLAPSUS$ | LAPSUS$ has payed employees, suppliers, and business partners of target organizations for credentials. |
| T1588.002 Tool |
GroupLAPSUS$ | LAPSUS$ has obtained tools such as RVTools and AD Explorer for their operations. |
| T1589.001 Credentials |
GroupLAPSUS$ | LAPSUS$ has gathered user identities and credentials to gain initial access to a victim's organization; the group has also called an organization's help desk to reset a target's credentials. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.