← Back to all threat actors

LAPSUS$

Also known as DEV-0537, Strawberry Tempest
Tracked as G1004

LAPSUS$ is cyber criminal threat group that has been active since at least mid-2021. LAPSUS$ specializes in large-scale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.

How we source and review actor profiles
Motivation
ransomware
Sectors
business-services, consumer-services, financial-services, technology, telecommunication
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityTracking identifier: G1004

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: DEV-0537

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Strawberry Tempest

Reviewed identity mapping approved on this date.

First listed
Victim claimAYA BANK listed by LAPSUS$

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimINGKA GROUP listed by LAPSUS$

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimVODAFONE listed by LAPSUS$

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimAXCERA TRADING listed by LAPSUS$

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimCHECKMARX listed by LAPSUS$

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

LAPSUS$Canonical Name
DEV-0537Alias
Strawberry TempestAlias
G1004Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...