ATT&CKReferencesNCC Group LAPSUS Apr 2022

NCC Group LAPSUS Apr 2022

Brown, D., et al. (2022, April 28). LAPSUS$: Recent techniques, tactics and procedures. Retrieved December 22, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1078
Valid Accounts
GroupLAPSUS$

LAPSUS$ has used compromised credentials and/or session tokens to gain access into a victim's VPN, VDI, RDP, and IAMs.

T1087.002
Domain Account
GroupLAPSUS$

LAPSUS$ has used the AD Explorer tool to enumerate users on a victim's network.

T1133
External Remote Services
GroupLAPSUS$

LAPSUS$ has gained access to internet-facing systems and applications, including virtual private network (VPN), remote desktop protocol (RDP), and virtual desktop infrastructure (VDI) including Citrix.

T1213.002
Sharepoint
GroupLAPSUS$

LAPSUS$ has searched a victim's network for collaboration platforms like SharePoint to discover further high-privilege account credentials.

T1213.003
Code Repositories
GroupLAPSUS$

LAPSUS$ has searched a victim's network for code repositories like GitLab and GitHub to discover further high-privilege account credentials.

T1485
Data Destruction
GroupLAPSUS$

LAPSUS$ has deleted the target's systems and resources both on-premises and in the cloud.

T1489
Service Stop
GroupLAPSUS$

LAPSUS$ has shut down virtual machines from within a victim's on-premise VMware ESXi infrastructure.

T1555.005
Password Managers
GroupLAPSUS$

LAPSUS$ has accessed local password managers and databases to obtain further credentials from a compromised network.

T1584.002
DNS Server
GroupLAPSUS$

LAPSUS$ has reconfigured a victim's DNS records to actor-controlled domains and websites.

T1586.002
Email Accounts
GroupLAPSUS$

LAPSUS$ has payed employees, suppliers, and business partners of target organizations for credentials.

T1588.002
Tool
GroupLAPSUS$

LAPSUS$ has obtained tools such as RVTools and AD Explorer for their operations.

T1589.001
Credentials
GroupLAPSUS$

LAPSUS$ has gathered user identities and credentials to gain initial access to a victim's organization; the group has also called an organization's help desk to reset a target's credentials.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.