logo

Unveiling the Tactics of Lapsus$: A Review of Internal Attacks Vectors, Mobile Device Exploitation, and Social Engineering Techniques

ID: 8f85c5e2-a7c3-5d07-be9c-4801f1e0ca95

STIX ID: report--8f85c5e2-a7c3-5d07-be9c-4801f1e0ca95

Feed Name: Zimperium Blog

Threat Score
70/100

Date Published: 2023-08-29

Date Updated: 2026-05-01

...
...

The DHS Cyber Safety Review Board reviewed Lapsus$ activity from late 2021 through 2022 and found a group of juveniles used simple but effective social-engineering techniques—spear-phishing, smishing, vishing, and MFA fatigue—to steal credentials, exfiltrate source code, extort dozens of major companies and government agencies, and deface sites; the report emphasizes failures in identity and access management, the risks of SMS/voice-based MFA, and recommends stronger controls and mobile-focused defenses while the document also includes Zimperium MTD marketing as a mitigation option.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.